-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Cisco Security Advisory: Multiple Vulnerabilities in the Cisco ACE
Application Control Engine Module and Cisco ACE 4710 Application
Control Engine
Document ID: 109450
Advisory ID: cisco-sa-20090225-ace
http://www.cisco.com/warp/public/707/cisco-sa-20090225-ace.shtml 
Revision 1.0
For Public Release 2009 February 25 1600 UTC (GMT)
- ---------------------------------------------------------------------
Summary
======
The Cisco ACE Application Control Engine Module and Cisco ACE 4710
Application Control Engine Cisco ACE Module and Cisco ACE 4710
Application Control Engine contain multiple vulnerabilities that, if
exploited, can could result in any of the following impacts:
  * Administrative level access via default user names and passwords
  * Privilege escalation
  * A denial of service (DoS) condition
Cisco has released free software updates available for affected
customers. Workarounds that mitigate some of the vulnerabilities are
available.
Note: These vulnerabilities are independent of each other. A device
may be affected by one vulnerability and not affected by another.
This advisory is posted at 
http://www.cisco.com/warp/public/707/cisco-sa-20090225-ace.shtml 
Note: This advisory is being released simultaneously with a multiple
vulnerability disclosure advisory that impacts the Cisco 4700 Series
Application Control Engine Device Manager and Application Networking
Manager module software.
This advisory is posted at 
http://www.cisco.com/warp/public/707/cisco-sa-20090225-anm.shtml 
Affected Products
================
Vulnerable Products
+------------------
The following table displays the products that are affected by each
vulnerability that is described within this advisory.
+-------------------------------------------------------------------+
|                                     | Products and Versions       |
|                                     | Affected                    |
|Vulnerability                        |-----------------------------|
|                                     | Cisco ACE    | Cisco ACE    |
|                                     | 4710         | Module       |
|                                     | Appliance    |              |
|-------------------------------------+--------------+--------------|
|                                     | All versions | All versions |
| Default Usernames and Passwords     | prior to A1  | prior to A2  |
|                                     | (8a)         | (1.1)        |
|-------------------------------------+--------------+--------------|
|                                     | All versions | All versions |
| Privilege Escalation Vulnerability  | prior to A1  | prior to A2  |
|                                     | (8a)         | (1.2)        |
|-------------------------------------+--------------+--------------|
|                                     | All versions | All versions |
| Crafted SSH Packet Vulnerability    | prior to A3  | prior to A2  |
|                                     | (2.1)        | (1.3)        |
|-------------------------------------+--------------+--------------|
| Crafted Simple Network Management   | All versions | All versions |
| Protocol version 2 (SNMPv2) Packet  | prior to A3  | prior to A2  |
| Vulnerability                       | (2.1)        | (1.3)        |
|-------------------------------------+--------------+--------------|
|                                     | All versions | All versions |
| Crafted SNMPv3 Packet Vulnerability | prior to A1  | prior to A2  |
|                                     | (8.0)        | (1.2)        |
+-------------------------------------------------------------------+
Determining Software Versions
+----------------------------
To display the version of system software that is currently running
on Cisco ACE Application Control Engine, use the show version
command. The following example displays the output of the show
version command on the Cisco ACE Application Control Engine software
version A3(1.0):
    ACE-4710/Admin# show version
    Cisco Application Control Software (ACSW)
TAC support: http://www.cisco.com/tac 
    Copyright (c) 1985-2008 by Cisco Systems, Inc. All rights reserved.
    The copyrights to certain works contained herein are owned by
    other third parties and are used and distributed under license.
    Some parts of this software are covered under the GNU Public
    License. A copy of the license is available at
http://www.gnu.org/licenses/gpl.html 
    Software
      loader:    Version 0.95
      system:    Version A3(1.0) [build 3.0(0)A3(0.0.148) adbuild_03:31:25-2008/08/06_/auto/adbure_nightly2/nightly_rel_a3_1_0_throttle/REL_3_0_0_A3_0_0
      system image file: (nd)/192.168.65.31/scimitar.bin
      Device Manager version 1.1 (0) 20080805:0415
    ...