Skip to main content

Cisco Network Admission Control Directory Traversal Vulnerability

Last Update Date: 7 Oct 2011 15:02 Release Date: 7 Oct 2011 5137 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in Cisco Network Admission Control (NAC), which can be exploited by malicious people to disclose sensitive information.

 

Certain input passed to the management interface via the URL is not properly verified before being used. This can be exploited to disclose the contents of arbitrary files via directory traversal sequences.


Impact

  • Information Disclosure

System / Technologies affected

  • Cisco NAC Appliance 4.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 4.9.

Vulnerability Identifier


Source


Related Link