Update Protection against Cisco Application Networking Manager Default User Credentials Security Bypass Vulnerability
| Check Point Reference: | CPAI-2009-046 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | cisco-sa-20090225-anm | |
| Industry Reference(s): | CVE-2009-0616 | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Cisco Systems Application Networking Manager (ANM) Prior to 2.0 | ||
| Vulnerability Description A security bypass vulnerability exists in Cisco Application Networking Manager (ANM). ANM is a network management application that manages Cisco Application Control Engine (ACE) modules or appliances. A remote attacker could exploit this vulnerability to take complete control of an affected system. |
||
|
Update/Patch Available Update the vulnerable product: cisco-sa-20090225-anm |
|
|
Vulnerability Details The vulnerability is due to a design error in the ANM that does not force credential changes during installation. A remote attacker may exploit this issue by accessing the ANM using default user credentials. Successful exploitation of this vulnerability could allow the attacker to take complete control of an affected system. |
Protection Overview
By enabling this protection, IPS will detect and block login attempts with default user credentials.
In order for the protection to be activated, update your Security Gateway product to the latest SmartDefense update.
To configure the defense, select your product from the list below and follow the related protection steps.