03-03-2014 09:29 AM - edited 02-21-2020 10:00 PM
Introduction
Due to the release of the Multiple Vulnerabilities in Cisco Secure Access Control System advisory an upgrade to ACS 5.5 is now required.
5.0 | 5.1 | 5.2 | 5.3 | 5.4 | |
Cisco Secure ACS RMI Privilege Escalation Vulernability | Migrate to 5.5 or later | Migrate to 5.5 or later | Migrate to 5.5 or later | Migrate to 5.5 or later | Migrate to 5.5 |
Cisco Secure ACS RMI Unauthenticated User Access Vulnerability | Migrate to 5.5 or later | Migrate to 5.5 or later | Migrate to 5.5 or later | Migrate to 5.5 or later | Migrate to 5.5 |
Cisco Secure ACS Operating System Command Injection Vulnerability | Migrate to 5.4 or later | Migrate to 5.4 or later | Migrate to 5.4 or later | Migrate to 5.4 or later | 5.4 Patch 3 |
First Fixed release for all vulnerabilities in this advisory | 5.5 |
New and Changed Features
The following sections briefly describe the new and changed features in the 5.5 release:
Due to CSCum04132 and CSCum26584, the following steps should be followed:
For 5.3 --> Pointed-PreUpgrade-CSCum04132-5-3-0-40.tar.gpg
For 5.4 --> Pointed-PreUpgrade-CSCum04132-5-4-0-46-0a.tar.gpg
Note: In case of a Distributed deployment scenario, please deregister the secondary from the primary before the upgrade. Once both appliances run 5.5, including the cumulatve patch, register the secondary again.
HTH.
- Javier
To upgrade from ACS 5.4 to 5.5 patch-1, it is VERY important to you need to run "compress-database" in ACS 5.4 prior to installing the Pointed-PreUpgrade-CSCum04132-5-4-0-46-0a.tar.gpg.
It happened to me when I tried to upgrade from ACS 5.4 to ACS 5.5 patch-1. The upgrade was not successful unless I ran "compress-database" prior to the Pointed-PreUpgrade-CSCum04132-5-4-0-46-0a.tar.gpg patch.
After I ran "compress-database", I then applied the Pointed patch, then the upgrade to ACS 5.5 went very smoothly.
Hi,
I haven't needed to run the database compress command, but you are right it is a good step and it is part of the success of the upgrade.
It is now included in the document.
Thanks for sharing your feedback.
Should the upgrade procedure also mention that if someone is running 5.0, 5.1 or 5.2 they should upgrade to 5.3 or 5.4 before uprgading to 5.5 ?
HI,
If I want to upgrade from ACS 5.5.0.46.x to 5.5.0.46.10, it can be done with the file 5-5-0-46-10.tar.gpg ?
Running the command:
Thanks
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: