TUCoPS :: Cisco :: ciack012.txt

Cisco Cache Engine Auth


           __________________________________________________________

                       The U.S. Department of Energy
                    Computer Incident Advisory Capability
                           ___  __ __    _     ___
                          /       |     /_\   /
                          \___  __|__  /   \  \___
             __________________________________________________________

                             INFORMATION BULLETIN

                  Cisco Cache Engine Authentication Vulnerabilities 

December 21, 1999 17:00 GMT                                       Number K-012
______________________________________________________________________________
PROBLEM:       Cisco has identified three Cache Engine vulnerabilities: 
	       1)  Allows unauthorized persons to substitute arbitrary 
                   material in place of legitimate content for a website. 
               2)  View performance information via web interface. 
               3)  Allow a null username and password pair to be accepted as 
                   valid authentication credentials. 
PLATFORM:      Cisco Cache Engine 2050, Release 1.0 through 1.7.6, Cisco 
               Cache Engine 500, Release 2.0.1 through 2.0.2. 
DAMAGE:        1)  Allow an opportunistic content provider to populate a Cisco 
		   Cache Engine with content of their choosing, yet make it 	
		   appear as any other host name was serving this content.
               2)  A script can be written to bypass an authentication request 
                   and gain access to the performance statistics without 
                   authentication.
               3)  Permit unauthorized persons to alter files on the Cache 
                   Engine.
SOLUTION:      Upgrade software to Cisco Cache Engine 500, Version 2.0.3. 
______________________________________________________________________________
VULNERABILITY  The risk is MEDIUM. Cisco knows of no public announcements of 
ASSESSMENT:    these vulnerabilities, nor have any malicious uses been reported 
	       to Cisco.
______________________________________________________________________________

[  Start Cisco Advisory  ]

Cisco Cache Engine Authentication Vulnerabilities

Revision 1.2

For public release Thursday, 1999 December 16, at 08:00AM US/Pacific (GMT-
0800)

  ===========================================================================

Summary
=======
   * A vulnerability exists that could allow an unauthorized person to
     substitute arbitrary material in place of legitimate content for a
     specified website.  This arbitrary content would be viewable only by 
     users of the affected (or "polluted") Cache Engine.  This vulnerability
     has Cisco bug ID CSCdm63310. 
   * A second vulnerability exists that could allow unauthorized persons to
     view performance information via the web interface of the Cache Engine.
     This vulnerability has Cisco bug ID CSCdp20180. 
   * A third vulnerability existed that allowed a null username and password
     pair to be accepted as valid authentication credentials.  This
     vulnerability has Cisco bug ID CSCdj56294. 

Who Is Affected
===============
If you are using a Cisco Cache Engine that has not been upgraded to version
2.0.3, you are vulnerable to the first two issues (CSCdm63310 and CSCdp20180).
If you are running a Cache Engine that has not been upgraded to version 1.5,
you are vulnerable to all three issues (CSCdm63310, CSCdp20180, and
CSCdj56294).

Impact
======
For Cisco bug ID CSCdm63310:

Content can be stored on the Cisco Cache Engine, provided a well-known host
name, and clients behind that Cisco Cache Engine will only receive the Cisco
Cache Engine content for that well-known host name.  This would allow an
opportunistic content provider to populate a Cisco Cache Engine with content
of their choosing, yet make it appear as any other host name was serving this
content.  The clients using this "polluted" cache engine would be the only
ones to see this tainted content, causing confusion and service disruption.
Version 2.0.3 of the Cisco Cache Engine provides additional authentication to
verify that the hostname provided actually belongs to the site providing the
content.

For Cisco bug ID CSCdp20180:

Though the Cache Engine web administration pages request authentication, a
script can be written to bypass the authentication request and gain access to
the performance statistics without authentication.  This problem has been
fixed by adding extra security checks to verify the Java monitor applet that
provides the performance statistics has been properly authenticated.

For Cisco bug ID CSCdj56294:

This issue would permit unauthorized persons to alter files on the Cache
Engine, ranging from blocked site lists to alternate software versions.  Very
few sites were provided versions affected by this issue.

Affected and Repaired Software Versions
=======================================
Cisco Cache Engine 2050, Release 1.0 through 1.7.6.
Cisco Cache Engine 500, Release 2.0.1 through 2.0.2.

All issues are fixed in the Cisco Cache Engine 500, Release 2.0.3 or later.

All issues are fixed in Cisco Cache Engine version 2.0.3. CSCdj56294 is
resolved in Cisco Cache Engine version 1.5, and higher.  However, due to
issues CSCdp20180 and CSCdm63310, it is strongly recommended that customers
upgrade to Cisco Cache Engine version 2.0.3.

Software version 2.0.3 will only apply to the following Cisco Cache Engine
Hardware platforms: CE-550, CE-505, and CE-550-DS3.  The CE-2050 chassis
cannot be upgraded to version 2.0.3, and you will need to contact the Cisco
TAC for assistance as detailed in the "Getting Fixed Software" section of this
notice.  If you do not know which hardware chassis of the Cisco Cache Engine
you have, please contact the Cisco TAC at one of the telephone numbers listed
in the "Cisco Security Procedures" section of this notice.

Getting Fixed Software
======================
If you have a service contract and do not have a CE-2050, please download the
new software from Cisco's Worldwide Web site at http://www.cisco.com/.  It is
located in the Software Center under the title "Cisco Web Cache Engine" within
the Internet Products listing.  If you do not have a service contract, please
call the Cisco TAC at one of the telephone numbers listed in the "Cisco
Security Procedures" section of this notice.  If you have the CE-2050
platform, please call the Cisco TAC at one of the telephone numbers listed in
the "Cisco Security Procedures" section of this notice.  Give the URL of this
notice as evidence of your entitlement to an upgrade.

Workarounds
===========
Workarounds to prevent an attacker from taking advantage of the vulnerability
described in CSCdm63310 include disabling the Cisco Cache Engine or specifying
a strict list of permitted sites that would restrict clients to a list of
known, valid websites.  The procedure for enabling URL restriction is detailed
in Cache Engine documentation version 1.7 at the following link:

 http://www.cisco.com/univercd/cc/td/doc/product/iaabu/webcache/ce17/ver17/wc1
7man.htm

Workarounds for both CSCdp20180 and CSCdj56294 include other means of limiting
access to both web based management and FTP ports on the Cache Engine, such as
firewalls or access lists on routers to limit traffic to those ports.

It is strongly recommended to upgrade to version 2.0.3 of the Cisco Cache
Engine.

Exploitation and Public Announcements
=====================================
These vulnerabilities were all originally reported to Cisco by separate
customers.  Cisco knows of no public announcements of these vulnerabilities,
nor have any malicious uses been reported to Cisco.

A simple HTML script is needed to effectively exploit CSCdp20180.  Although
Cisco knows of no program available to the public specifically for this
purpose, writing such a script would require little effort, and a basic
understanding of HTML and Java code.

Status of This Notice
=====================
This is a final field notice.  Although Cisco cannot guarantee the accuracy of
all statements in this notice, all the facts have been checked to the best of
our ability.  Cisco does not anticipate issuing updated versions of this
notice unless there is some material change in the facts.  Should there be a
significant change in the facts, Cisco may update this notice.

Distribution
- ------------
This notice will be posted on Cisco's Worldwide Web site at
http://www.cisco.com/warp/public/707/cacheauth.shtml.  In addition to
Worldwide Web posting, the initial version of this notice is being sent to the
following e-mail and Usenet news recipients:

   * cust-security-announce@cisco.com
   * bugtraq@securityfocus.com
   * first-teams@first.org (includes CERT/CC)
   * first-info@first.org
   * cisco@spot.colorado.edu
   * comp.dcom.sys.cisco
   * Various internal Cisco mailing lists

Future updates of this notice, if any, will be placed on Cisco's Worldwide Web
server, but may or may not be actively announced on mailing lists or
newsgroups.  Users concerned about this problem are encouraged to check the
URL given above for any updates.

Revision History
- ----------------
 Revision1.0,
 8:00 AM US/Pacific,   Initial public release.
 1999-Dec-16

 Revision1.1,
 8:00 AM US/Pacific,   Various punctuation fixes.
 1999-Dec-16

 Revision1.2,
 9:00 AM US/Pacific,   Various content fixes.
 1999-Dec-16,

Cisco Security Procedures
=========================
Cisco's Worldwide Web site contains complete information for reporting
security vulnerabilities in Cisco products, obtaining assistance with security
incidents, and registering to receive security information directly from Cisco
at http://www.cisco.com/warp/public/791/sec_incident_response.shtml.  This
includes instructions for press inquiries regarding Cisco security notices.

  ---------------------------------------------------------------------------
This notice is copyright 1999 by Cisco Systems, Inc.  This notice may be
redistributed freely after the release date given at the top of the notice,
provided that redistributed copies are complete and unmodified, including all
date and version information.
  ---------------------------------------------------------------------------


[  End Cisco Advisory  ]

______________________________________________________________________________

CIAC wishes to acknowledge the contributions of Cisco for the 
information contained in this bulletin.
______________________________________________________________________________


CIAC, the Computer Incident Advisory Capability, is the computer
security incident response team for the U.S. Department of Energy
(DOE) and the emergency backup response team for the National
Institutes of Health (NIH). CIAC is located at the Lawrence Livermore
National Laboratory in Livermore, California. CIAC is also a founding
member of FIRST, the Forum of Incident Response and Security Teams, a
global organization established to foster cooperation and coordination
among computer security teams worldwide.

CIAC services are available to DOE, DOE contractors, and the NIH. CIAC
can be contacted at:
    Voice:    +1 925-422-8193
    FAX:      +1 925-423-8002
    STU-III:  +1 925-423-2604
    E-mail:   ciac@llnl.gov

For emergencies and off-hour assistance, DOE, DOE contractor sites,
and the NIH may contact CIAC 24-hours a day. During off hours (5PM -
8AM PST), use one of the following methods to contact CIAC:

    1.  Call the CIAC voice number 925-422-8193 and leave a message, or

    2.  Call 888-449-8369 to send a Sky Page to the CIAC duty person or

    3.  Send e-mail to 4498369@skytel.com, or

    4.  Call 800-201-9288 for the CIAC Project Leader.

Previous CIAC notices, anti-virus software, and other information are
available from the CIAC Computer Security Archive.

   World Wide Web:      http://www.ciac.org/
                        (or http://ciac.llnl.gov -- they're the same machine)
   Anonymous FTP:       ftp.ciac.org
                        (or ciac.llnl.gov -- they're the same machine)
   Modem access:        +1 (925) 423-4753 (28.8K baud)
                        +1 (925) 423-3331 (28.8K baud)

CIAC has several self-subscribing mailing lists for electronic
publications:
1. CIAC-BULLETIN for Advisories, highest priority - time critical
   information and Bulletins, important computer security information;
2. SPI-ANNOUNCE for official news about Security Profile Inspector
   (SPI) software updates, new features, distribution and
   availability;
3. SPI-NOTES, for discussion of problems and solutions regarding the
   use of SPI products.

Our mailing lists are managed by a public domain software package
called Majordomo, which ignores E-mail header subject lines. To
subscribe (add yourself) to one of our mailing lists, send the
following request as the E-mail message body, substituting
ciac-bulletin, spi-announce OR spi-notes for list-name:

E-mail to       ciac-listproc@llnl.gov or majordomo@rumpole.llnl.gov:
        subscribe list-name 
  e.g., subscribe ciac-bulletin 

You will receive an acknowledgment E-mail immediately with a confirmation
that you will need to mail back to the addresses above, as per the
instructions in the E-mail.  This is a partial protection to make sure
you are really the one who asked to be signed up for the list in question.

If you include the word 'help' in the body of an E-mail to the above address,
it will also send back an information file on how to subscribe/unsubscribe,
get past issues of CIAC bulletins via E-mail, etc.

PLEASE NOTE: Many users outside of the DOE, ESnet, and NIH computing
communities receive CIAC bulletins.  If you are not part of these
communities, please contact your agency's response team to report
incidents. Your agency's team will coordinate with CIAC. The Forum of
Incident Response and Security Teams (FIRST) is a world-wide
organization. A list of FIRST member organizations and their
constituencies can be obtained via WWW at http://www.first.org/.

This document was prepared as an account of work sponsored by an
agency of the United States Government. Neither the United States
Government nor the University of California nor any of their
employees, makes any warranty, express or implied, or assumes any
legal liability or responsibility for the accuracy, completeness, or
usefulness of any information, apparatus, product, or process
disclosed, or represents that its use would not infringe privately
owned rights. Reference herein to any specific commercial products,
process, or service by trade name, trademark, manufacturer, or
otherwise, does not necessarily constitute or imply its endorsement,
recommendation or favoring by the United States Government or the
University of California. The views and opinions of authors expressed
herein do not necessarily state or reflect those of the United States
Government or the University of California, and shall not be used for
advertising or product endorsement purposes.

LAST 10 CIAC BULLETINS ISSUED (Previous bulletins available from CIAC)

K-002: Microsoft IE 5 Vulnerability - "download behavior"
K-003: Windows NT 4.0 does not delete Unattended Installation File
K-004: Microsoft "Excel SYLK" Vulnerability
K-005: Microsoft "Virtual Machine Verifier" Vulnerability
K-006: Microsoft - Improve TCP Initial Sequence Number Randomness
K-007: Multiple Vulnerabilities in BIND
K-008: ExploreZip (packed) Worm
K-009: Qpopper Buffer Overflow Vulnerability
K-010: Solaris Snoop Buffer Overflow Vulnerability
K-011: Buffer Overflow Vulnerabilities in SSH Daemon and RSAREF2



TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2025 AOH