03-25-2015 08:14 PM - edited 03-10-2019 10:35 PM
We came to know frm our compliance team that we are running into shell shock vulnerabity therefore wanted to know the fix and document..
Solved! Go to Solution.
03-25-2015 08:16 PM
Hi James,
We do have a PSIRT filed for shell shock vulnerability, please refer details below:
CSCur00511 ACS evaluation for CVE-2014-6271 and CVE-2014-7169
https://tools.cisco.com/bugsearch/bug/CSCur00511/?reffering_site=dumpcr
Here is the fixed code information for individual versions:
Fixed Code:
Patch for DDTS CSCur00511 is ready and available on CCO.
The patch is included in all cumulative patches from version 5.4.0.46.7/5.5.0.46.6/5.6.0.22.1 and later. We recommend that you download the latest cumulative patches.
Download from: CCO / Support / Download Software http://www.cisco.com/cisco/pub/software/portal/select.html?i=!y
Select: Security / Identity Management / Cisco Secure Access Control System / Cisco Secure Access Control System 5.4 / 5.4.0.46.0
Patch filename: 5-4-0-46-.tar.gpg
Readme and installaion instructions: Acs-5-4-0-46--Readme.txt
Download from: CCO / Support / Download Software http://www.cisco.com/cisco/pub/software/portal/select.html?i=!y
Select: Security / Identity Management / Cisco Secure Access Control System / Cisco Secure Access Control System 5.5 / 5.5.0.46
Patch filename: 5-5-0-46-.tar.gpg
Readme and installaion instructions: Acs-5-5-0-46--Readme.txt
Download from: CCO / Support / Download Software http://www.cisco.com/cisco/pub/software/portal/select.html?i=!y
Select: Security / Identity Management / Cisco Secure Access Control System / Cisco Secure Access Control System 5.6 / 5.6.0.22
Patch filename: 5-6-0-22-.tar.gpg
Readme and installaion instructions: Acs-5-6-0-22--Readme.txt
Download from: CCO / Support / Download Software http://www.cisco.com/cisco/pub/software/portal/select.html?i=!y
Select: Security / Identity Management / Cisco Secure Access Control System / Cisco Secure Access Control System 5.3 / 5.3.0.40
Patch filename: 5-3-0-40-.tar.gpg
Readme and installaion instructions: Acs-53-Readme.txt
Regards,
Tushar Bangia
Please do rate the post if you find it helpful!!
03-25-2015 08:16 PM
Hi James,
We do have a PSIRT filed for shell shock vulnerability, please refer details below:
CSCur00511 ACS evaluation for CVE-2014-6271 and CVE-2014-7169
https://tools.cisco.com/bugsearch/bug/CSCur00511/?reffering_site=dumpcr
Here is the fixed code information for individual versions:
Fixed Code:
Patch for DDTS CSCur00511 is ready and available on CCO.
The patch is included in all cumulative patches from version 5.4.0.46.7/5.5.0.46.6/5.6.0.22.1 and later. We recommend that you download the latest cumulative patches.
Download from: CCO / Support / Download Software http://www.cisco.com/cisco/pub/software/portal/select.html?i=!y
Select: Security / Identity Management / Cisco Secure Access Control System / Cisco Secure Access Control System 5.4 / 5.4.0.46.0
Patch filename: 5-4-0-46-.tar.gpg
Readme and installaion instructions: Acs-5-4-0-46--Readme.txt
Download from: CCO / Support / Download Software http://www.cisco.com/cisco/pub/software/portal/select.html?i=!y
Select: Security / Identity Management / Cisco Secure Access Control System / Cisco Secure Access Control System 5.5 / 5.5.0.46
Patch filename: 5-5-0-46-.tar.gpg
Readme and installaion instructions: Acs-5-5-0-46--Readme.txt
Download from: CCO / Support / Download Software http://www.cisco.com/cisco/pub/software/portal/select.html?i=!y
Select: Security / Identity Management / Cisco Secure Access Control System / Cisco Secure Access Control System 5.6 / 5.6.0.22
Patch filename: 5-6-0-22-.tar.gpg
Readme and installaion instructions: Acs-5-6-0-22--Readme.txt
Download from: CCO / Support / Download Software http://www.cisco.com/cisco/pub/software/portal/select.html?i=!y
Select: Security / Identity Management / Cisco Secure Access Control System / Cisco Secure Access Control System 5.3 / 5.3.0.40
Patch filename: 5-3-0-40-.tar.gpg
Readme and installaion instructions: Acs-53-Readme.txt
Regards,
Tushar Bangia
Please do rate the post if you find it helpful!!
03-25-2015 08:17 PM
Thanks for info man!!
This is helpful..
03-25-2015 08:19 PM
Please do share the link for patch!!
03-25-2015 08:22 PM
Here is the link for ACS 5.5!!
https://software.cisco.com/download/release.html?mdfid=285954966&flowid=73107&softwareid=282766937&release=5.5.0.46&relind=AVAILABLE&rellifecycle=&reltype=latest
03-25-2015 08:23 PM
Thx mayte!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide