Cisco Application Control Engine Login Administrator IP Address Overlap (cisco-sa-20120620-ace)

This script is Copyright (C) 2013-2016 Tenable Network Security, Inc.

Synopsis :

The remote device is missing a vendor-supplied security patch.

Description :

The Cisco Application Control Engine (ACE) software installed on the
remote Cisco IOS device is earlier than A4(2.3) / A5(1.1). It,
therefore, potentially does not properly share a management IP address
among multiple contexts when multicontext mode is enabled. This might
allow an administrative user to be logged into an unintended context
(virtual instance) on the ACE when two or more contexts are configured
with the same management IP address.

See also :

Solution :

Apply the relevant patch referenced in Cisco Security Advisory

Risk factor :

High / CVSS Base Score : 7.1
CVSS Temporal Score : 5.9
Public Exploit Available : true

Family: CISCO

Nessus Plugin ID: 69914 ()

Bugtraq ID: 54129

CVE ID: CVE-2012-3063

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now