Cisco Content Service Switch Management Authentication Bypass Vulnerability

The Cisco Content Service Switch is an enterprise level web content switch, designed for load balancing and use as a frontend to a redundant web farm. It was previously manufactured by Arrowpoint.

A problem with the switch can make it possible for a user to elevated privileges. Due to insufficent authentication checking, a user can bookmark the URL he or she is redirected to, and access the switch via that URL without authenication.

This makes it possible for a user gain management privileges on a Content Service Switch without authenication, and could lead to denial of service or alteration of sensitive information.


 

Privacy Statement
Copyright 2010, SecurityFocus