Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Cisco Secure ACS Insecure Password Storage Vulnerability

Cisco Secure ACS is susceptible to an insecure password-storage vulnerability. This issue is due to a failure of the application to properly secure sensitive password information.

This issue allows attackers to gain access to encrypted passwords and to the key used to encrypt them. This allows them to obtain the plaintext passwords, aiding them in attacking other services that depend on the ACS server for authentication.

Cisco Secure Access Control Server for Windows versions 3.x are affected by this issue.







 

Privacy Statement
Copyright 2009, SecurityFocus