{"vuid":"VU#352462","idnumber":"352462","name":"Cisco ACNS contains buffer overflow vulnerability in the authentication module when supplied an overly long password","keywords":["Cisco","ACNS","buffer overflow","authentication module","overly long password"],"overview":"Cisco Application and Content Networking Software (ACNS) contains a buffer overflow that may enable an attacker to execute arbitrary code on the affected device.","clean_desc":"Cisco ACNS Software \"...combines demand-pull caching and pre-positioning for accelerated delivery of web applications, objects, files, and streaming media; and runs on Cisco Content Engines, Content Distribution Manager, and Content Router hardware platforms.\"  From http://www.cisco.com/warp/public/707/cisco-sa-20031210-ACNS-auth.shtml: By entering an overly long password, it may be possible to execute arbitrary code on a vulnerable device. This vulnerability affects all devices and hardware modules that are running ACNS software releases prior to 4.2.11 and 5.0.5. According to the Cisco advisory the hardware models that supports ACNS are: Content Routers 4400 series\nContent Distribution Manager 4600 series\nContent Engine 500 and 7300 series\nContent Engine Module for Cisco Routers 2600, 3600 and 3700 series\nThis issue has been assigned Cisco bug IDs CSCeb25596 and CSCeb27087.","impact":"By supplying an overly long password, it is possible to trigger a buffer overflow in the authentication module. This may enable an attacker to execute arbitrary code on the affected device or cause denial of service.","resolution":"Upgrade\nUpgrade ACNS software as referenced in http://www.cisco.com/warp/public/707/cisco-sa-20031210-ACNS-auth.shtml. This vulnerability is fixed in 4.2.11 and 5.0.5 releases of ACNS.","workarounds":"Disable Content Engine GUI The workaround is to disable the CE GUI server using the following command: no gui-server enable","sysaffected":"","thanks":"This vulnerability was reported by the Cisco Systems Product Security Incident Response Team.","author":"This document was written by Robert C Seacord.","public":["http://www.cisco.com/warp/public/707/cisco-sa-20031210-ACNS-auth.shtml","http://www.secunia.com/advisories/10409/","http://xforce.iss.net/xforce/xfdb/13945","http://www.securityfocus.com/bid/9187"],"cveids":["CVE-2003-0982"],"certadvisory":"","uscerttechnicalalert":null,"datecreated":"2003-12-10T18:22:47Z","publicdate":"2003-12-10T00:00:00Z","datefirstpublished":"2003-12-18T16:46:07Z","dateupdated":"2003-12-23T15:05:03Z","revision":20,"vrda_d1_directreport":"","vrda_d1_population":"","vrda_d1_impact":"","cam_widelyknown":"15","cam_exploitation":"0","cam_internetinfrastructure":"15","cam_population":"8","cam_impact":"20","cam_easeofexploitation":"8","cam_attackeraccessrequired":"18","cam_scorecurrent":"12.96","cam_scorecurrentwidelyknown":"15.12","cam_scorecurrentwidelyknownexploited":"23.76","ipprotocol":"","cvss_accessvector":"","cvss_accesscomplexity":"","cvss_authentication":null,"cvss_confidentialityimpact":"","cvss_integrityimpact":"","cvss_availabilityimpact":"","cvss_exploitablity":null,"cvss_remediationlevel":"","cvss_reportconfidence":"","cvss_collateraldamagepotential":"","cvss_targetdistribution":"","cvss_securityrequirementscr":"","cvss_securityrequirementsir":"","cvss_securityrequirementsar":"","cvss_basescore":"","cvss_basevector":"","cvss_temporalscore":"","cvss_environmentalscore":"","cvss_environmentalvector":"","metric":12.96,"vulnote":null}