积极预防 及时发现
快速响应 力保恢复
Cisco Secure ACS是一个运行于Windows NT/2001和Unix平台的易升级、高...
发布时间:2002-03-12 信息来源:管理员

CNCVE编号:CNCVE-20020062 CVE编号: 安全级别:高 漏洞中文描述: Cisco Secure ACS是一个运行于Windows NT/2001和Unix平台的易升级、高性能的访问控制服务程序。它作为Remote Access Dial-In User Service (RADIUS)或TACACS+服务系统的控制中心来控制验证用户对网络资源的访问。 Windows NT下已经配置了NDS服务(Novell Directory Services)的Cisco Secure ACS存在一个安全漏洞,NDS数据库中已经过期失效或被禁止的用户帐号仍然可以成功通过服务的验证。 漏洞英文描述: Cisco Secure ACS is a highly scalable, high-performance access control server that runs on Windows NT/2000 operating systems and Unix variants. It operates as a centralized Remote Access Dial-In User Service (RADIUS) or TACACS+ server system and controls the authentication of users accessing resources through the network. A vulnerability has been discovered in Cisco Secure ACS for Windows NT that have been configured for NDS (Novell Directory Services). Users in the NDS database whose accounts have expired or been disabled may still successfully authenticate with the service. An expired or disabled user who authenticates with the correct credentials will still be able to access the service. The normal, expected behavior is that their access to the service will be denied. It should be noted that only Cisco Secure ACS 3.01 for Windows NT is prone to this issue. 漏洞参考: http://www.cisco.com/warp/public/707/ciscosecure-acs-nds-authentication-vuln-pub.shtml 系统类型: Win2000/NT 漏洞类型:设计错误