Threat Advisory

Cisco TS Agent Firewall Rules Bypass Vulnerability Allows Remote Attackers to Inherit Different User's

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules associated with the account of the attacker. This flaw is due to an incorrect mapping of network connections to user accounts, which can be exploited by sending crafted network traffic to an affected device. An attacker with at least user-level credentials could inherit the firewall rules associated with a different user in the system, resulting in unauthorized access to sensitive resources. The business impact of this vulnerability is significant, as it allows attackers to bypass security measures and gain access to sensitive data or systems. The CVSS score for this vulnerability is 5.0 (Medium), indicating a moderate risk level. Cisco has released software updates that address this issue, but there are no workarounds available at this time.

RECOMMENDATION:

We recommend you to update Cisco TS Agent to the 1.4.3 version.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules associated with the account of the attacker. This flaw is due to an incorrect mapping of network connections to user accounts, which can be exploited by sending crafted network traffic to an affected device. An attacker with at least user-level credentials could inherit the firewall rules associated with a different user in the system, resulting in unauthorized access to sensitive resources. The business impact of this vulnerability is significant, as it allows attackers to bypass security measures and gain access to sensitive data or systems. The CVSS score for this vulnerability is 5.0 (Medium), indicating a moderate risk level. Cisco has released software updates that address this issue, but there are no workarounds available at this time.

RECOMMENDATION:

We recommend you to update Cisco TS Agent to the 1.4.3 version.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu