>> Cisco Network Admission Control Shared Secret Disclosure Vulnerability
Title : Cisco Network Admission Control Shared Secret Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2008-1248 CVE ID : CVE-2008-1155
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-17
Technical Description
A vulnerability has been identified in Cisco Network Admission Control (NAC), which could be exploited by attackers to gain knowledge of sensitive information and compromise a vulnerable system. This issue is caused by an unspecified error that can allow an attacker to obtain the shared secret used by the Cisco Clean Access Server (CAS) and the Cisco Clean Access Manager (CAM) from error logs that are transmitted over the network, and gain complete control of a vulnerable CAS remotely over the network.