Cisco Security Agent Management Center Code Execution Vulnerability
24 Apr. 2011
Summary
The Management Center for Cisco Security Agent is affected by a vulnerability that may allow an unauthenticated attacker to perform remote code execution on the affected device.
Immune Systems:
* Cisco Security Agent software versions 6.0.2.145 and later
* Cisco Security Agent installations on end-point workstations or servers are not affected by this vulnerability.
The Management Center for Cisco Security Agent is affected by a vulnerability that could allow an unauthenticated attacker to perform remote code execution on the affected device. A successful exploit could allow the attacker to modify agent policies and system configuration and perform other administrative tasks.
Successful exploitation of the vulnerability could allow an unauthenticated attacker to perform remote code execution on the affected device and to perform agent policy modification, system configuration, and other administrative tasks.
Note: This vulnerability can be exploited only by sending certain packets to the web management interface, which by default listens on TCP port 443.
Workaround:
The following policy can be configured as a workaround to mitigate this vulnerability. Complete the following steps to deploy this policy for the Cisco Security Agent running on the Management Center for Cisco Security Agent server.
Create a New Application Class
Step 1. Specify the name of the application class as 'CSA MC - all applications but not its descendants'.
Step 2. Select when created from one of the following executables in the Add Process to application class area and specify @(regpath HKLM\SOFTWARE\Cisco\CSAMC60\ProductRootDir default=**\CSAMC*)\**\*.exe as the value.
Step 3. Ensure that the Only this process option is selected.
Step 4. Click Save.
Create a priority deny Application Control Rule
Step 1. Name the APCR as CSAMC applications invoking non-CSAMC applications for better readability.
Step 2. Enable logging.
Step 3. For Current applications in any of the following selected classes select the application class created under "Create a New Application Class." For the But not option, select .
Step 4. For New applications in any of the following selected classes select . For the But not option, select the new application class created under "Create a New Application Class."