• On All Site
  • Text Pages
  • Catalogue
  • News
  • News
    • Company news
    • IT news
  • About company
    • Company mission
    • Company structure
    • Team
    • Licenses and Certificates
    • Why our company
  • Services
    • DS Certification Authority
    • Custom Development
      • Software development
      • Hardware development
    • Consulting
    • Research
    • IT-outsourcing
  • On-line Shop
  • Job opportunities
    • Open positions
    • Technologies
  • Contacts
    News Sections
    Company news
    IT news
    News Archive
    2009
    January (6)
    March (1)
    May (1)
    July (1)
    September (1)
    February (4)
    April (2)
    June (1)
    August (2)
    November (1)
    2008
    December (2)
    News posting
    Company news
    IT news
    Подписаться
    IT news
    Patches for Cisco Security Manager
    26 January 2009

    Cisco warns that the combination of Cisco Security Manager server and the IPS Event Viewer (IEV) may allow unauthorised access to the underlying MySQL database or the IEV server. It says the cause of the problem is that when the the IEV application is launched it opens remotely accessible ports on the Cisco Security Manager server and on the client. Although when the IEV is subsequently closed, it closes the client ports, it leaves the Cisco Security Manager server ports open. That leaves the door open, with no requirement for authentication, allowing an un-athenticated attacker to access the MySQL database without alerts being reported by the Intrusion Prevention System. Cisco Security Manager versions 3.1, 3.1.1.SP3, 3.2.SP2 and 3.2.1.SP1 are affected. Version 3.2.2 doesn't contain the bug. Cisco is providing registered clients with patches for versions 3.1, 3.1.1, 3.2 and 3.2.1.
    http://www.heise-online.co.uk

    ← Back
    -- -- - - - - - - -- - - - - -- - -- - - - - - -- - -- - - - - - - - - -- ------------ ---- -- - -- - - - - -- - - -- - - -- - - - - -- - -- - - - - - - -- - - - - -- -- --- -- --- -- --
    NewsAbout companyServicesOn-line ShopJob opportunitiesContacts
    Copyright © 2009 Cryptomach LTD. All rights reserved.
    Development: Rireg.net