cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1996
Views
0
Helpful
2
Replies

IOS HTTP Authorization Vulnerability When Traversing ACE 4710????

cbregeripr
Level 1
Level 1

We had a PCI security audit of an existing VIP on our ACE 4710. The VIP is set up as HTTPS terminating on the ACE with a http redirect for all 80 traffic.  The audit reported this VIP was vunerabled to the Cisco "IOS HTTP Authorization Vulnerability".  Which basicly states, http Management is on this IOS device.  It does not make any sense, as the VIP is pointed to a pair IIS servers, Any ideas?

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20010627-ios-http-level

1 Accepted Solution

Accepted Solutions

chrhiggi
Level 3
Level 3

Chris-

  There is no way to issue a command to the CLI of ACE by hitting a VIP, the tool is reporting a false positive.

Regards,

Chris Higgins

View solution in original post

2 Replies 2

chrhiggi
Level 3
Level 3

Chris-

  There is no way to issue a command to the CLI of ACE by hitting a VIP, the tool is reporting a false positive.

Regards,

Chris Higgins

It turns the webserver behind the VIP, was returing a page when you sent a HTML GET to https://www.mysite.com/level/16/exec/-  This was being a recoded as a security vulnerability.  Thanks for the sanity check!

Review Cisco Networking for a $25 gift card