Cisco Application Control Engine Login Administrator IP Address Overlap (cisco-sa-20120620-ace)

This script is Copyright (C) 2013-2016 Tenable Network Security, Inc.


Synopsis :

The remote device is missing a vendor-supplied security patch.

Description :

The Cisco Application Control Engine (ACE) software installed on the
remote Cisco IOS device is earlier than A4(2.3) / A5(1.1). It,
therefore, potentially does not properly share a management IP address
among multiple contexts when multicontext mode is enabled. This might
allow an administrative user to be logged into an unintended context
(virtual instance) on the ACE when two or more contexts are configured
with the same management IP address.

See also :

http://www.nessus.org/u?908fe0cb

Solution :

Apply the relevant patch referenced in Cisco Security Advisory
cisco-sa-20120620-ace.

Risk factor :

High / CVSS Base Score : 7.1
(CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C)
CVSS Temporal Score : 5.9
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: CISCO

Nessus Plugin ID: 69914 ()

Bugtraq ID: 54129

CVE ID: CVE-2012-3063

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial