topics that matter; ideas worth sharing

share a tip, submit a link, add something new

Vulnerabilities uncovered in Cisco VPN client software

September 20, 2002, 03:05 PM —  ITworld.com — 

New vulnerabilties discovered in the Cisco Virtual Private Network (VPN) 5000 Client software could allow an attacker to gain root access to a local workstation running the VPN client software or to capture password information used by the client, according to statements released by security company Ubizen NV and by Cisco Systems, Inc. Thursday.

The root access vulnerability affects versions of the VPN 5000 Client for Linux and Solaris, while the password vulnerability affects the VPN 5000 Client for Macintosh.

Cisco, in San Jose California, released a security advisory covering the vulnerabilities late Wednesday, and provided links to the related Cisco bug identifiers and software updates on its Web site.

In the case of the vulnerability affecting VPN 5000 clients for the Linux and Solaris, two buffer overflow conditions were discovered by engineers at Ubizen, based in Reston, Virginia, that could enable an attacker who was logged on to the remote workstation to assign root privileges to their own log-in account, essentially giving that user total administrative control of the workstation and open access to data stored on that machine. The vulnerability was discovered during testing of the VPN 5000 Client by Ubizen, a Cisco Managed Security Services partner.

By exploiting buffer overflows in the close_tunnel and open_tunnel binaries used by the client, attackers could alter processes used by the client that have root privileges on the local machine, transferring those privileges to the user's log-in account, said Niels Heinen, a security assurance engineer at Ubizen.

The overflow condition is easy to exploit and doesn't require any special knowledge of VPN technology according to Heinen, who reported the issue to Cisco in early July.

"It's an easy exploit -- the kind you see in buffer overflow tutorials. It doesn't require a tremendous amount of technical knowledge to use it," Heinen said.

The buffer overflow vulnerability would require local access to the machine running the VPN Client, and would only compromise the security of the local workstation, not the security of the remote networks connected to by the VPN Client, Heinen said.

The vulnerabilities affect Cisco VPN Client software version 5.2.7 for Linux and VPN Client software version 5.2.8 for Solaris. Cisco assigned bug ID CSCdy20065 to the vulnerability.

In the case of the VPN Client password vulnerability affecting VPN 5000 clients for the Mac operating system, it was discovered that the password used to log in to a remote network connection was being stored in clear text and could easily be read by an attacker using a common resource editing tool such as ResEdit, providing the attacker had access to the remote workstation.

The bug affects all Cisco VPN 5000 Client software prior to version 5.2.2. Cisco assigned bug ID CSCdx17109 to the vulnerability.

This was the second security advisory affecting Cisco's VPN technology to be released in the last month. On Sept. 6, Cisco issued a pair of security advisories concerning vulnerabilities it had discovered in its VPN 3000 Client and its line of VPN 3000 concentrators.

Software patches for those vulnerabilities, as well as the two discovered this week are posted on Cisco's Web site. Cisco is encouraging its customers using the VPN 5000 Client on affected operating systems to upgrade to the latest version of its client software.

ITworld.com

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff
Featured Sponsor

Get a broad understanding of important regulations and how you can make sure your site is in adherence.





Learn how VeriSign SGC-enabled SSL Certificates can help improve site security and customer confidence in the free white paper, "How to Offer the Strongest SSL Encryption." In this paper you will learn the differences between weak and strong encryption and what they mean for your site's performance.

Get VeriSign's free white paper: "The Latest Advancements in SSL Technology" and learn about the benefits of strong SSL encryption, Extended Validation (EV) SSL and security trust marks and what these SSL offerings can do for your site.

Now with Extended Validation (EV) SSL available from VeriSign, you can show your customers that they can trust your site. Learn about EV SSL benefits in this free VeriSign white paper.

More Resources