Cisco Application Control Engine Login Administrator IP Address Overlap (cisco-sa-20120620-ace)

This script is Copyright (C) 2013 Tenable Network Security, Inc.


Synopsis :

The remote device is missing a vendor-supplied security patch.

Description :

The Cisco Application Control Engine (ACE) software installed on the
remote Cisco IOS device is earlier than A4(2.3) / A5(1.1). It,
therefore, potentially does not properly share a management IP address
among multiple contexts when multicontext mode is enabled. This might
allow an administrative user to be logged into an unintended context
(virtual instance) on the ACE when two or more contexts are configured
with the same management IP address.

See also :

http://www.nessus.org/u?908fe0cb

Solution :

Apply the relevant patch referenced in Cisco Security Advisory
cisco-sa-20120620-ace.

Risk factor :

High / CVSS Base Score : 7.1
(CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C)
CVSS Temporal Score : 5.9
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: CISCO

Nessus Plugin ID: 69914 ()

Bugtraq ID: 54129

CVE ID: CVE-2012-3063