Risk: High
A locally exploitable vulnerability in various Cisco CSA products has been reported by the French security firm FrSIRT. This flaw is due to a design error where software executed locally can bypass systems protections and run with elevated privileges, which could be exploited by malicious users to execute arbitrary commands with SYSTEM privileges and gain full control of the system, including the disabling of the CSA agent.
Upgrade information:
Upgrade to Management Center for Cisco Security Agents maintenance version 4.5.1.639:
- http://www.cisco.com/pcgi-bin/tablebuild.pl/csa
- Upgrade to CSA for CallManager version 4.5.1.639:
http://www.cisco.com/pcgi-bin/tablebuild.pl/cmva-3des - Upgrade to CSA for ICM, IPCC Enterprise, and IPCC Hosted version 4.5.1.639:
http://www.cisco.com/pcgi-bin/tablebuild.pl/csa10-crypto - Upgrade to CSA for CVP 3.0 and 3.1 version 4.5.1.639:
http://www.cisco.com/pcgi-bin/tablebuild.pl/csa-cvp-20