Title: Cisco PIX TACACS+ Denial of Service Vulnerability
Severity: HIGH
Description:
PIX is an enterprise firewall engineered and maintained by Cisco Systems. It is designed to provide robust features and multiple methods of access control and filtering.
A problem with the implementation of the TACACS+ protocol and access control of web resources in some versions of the firmware used on the Cisco PIX makes it possible for a both an internal and remote user to deny service to all users of network assets.
TACACS+ can be used to authenticate internal and external users of a virtual private network, as well as restrict access to certain network services crossing the PIX. The PIX acts as a proxy mechanism to serve the request from the client to the TACACS+/RADIUS server. Members of the group authorized access to controlled resources are placed in the authentication, authorization, and accounting (aaa) access control list.
A user from the internal side of the PIX that is not a member of the aaa group can crash a PIX by generating an excessive amount of requests for controlled resources, each of which requires a TACACS+ authentication before being granted. Once an approximate amount of 426 requests have been reached, the firewall becomes unstable and crashes. Recovery of normal operation requires power cycling of the firewall.
Similarly, an external user can attempt VPN access requiring TACACS+ authentication, and upon generating a large amount of requests for an internal service for which they're not authorized, consume all resources on the PIX and crash the firewall.
All PIX Firewalls having configuration lines beginning with the following line are affected:
pixfirewall# aaa authentication
Any configurations not including aaa authentication are not affected.
Affected Products:
- Cisco PIX Firewall 4.0.0
- Cisco PIX Firewall 4.1.6
- Cisco PIX Firewall 4.1.6b
- Cisco PIX Firewall 4.2.0(5)
- Cisco PIX Firewall 4.2.1
- Cisco PIX Firewall 4.2.2
- Cisco PIX Firewall 4.3.0
- Cisco PIX Firewall 4.4.0(4)
- Cisco PIX Firewall 4.4.0(7.202)
- Cisco PIX Firewall 4.4.0(8)
- Cisco PIX Firewall 5.0.0
- Cisco PIX Firewall 5.1.0
- Cisco PIX Firewall 5.1.4
- Cisco PIX Firewall 5.2.0(2)
- Cisco PIX Firewall 5.3.0
- Cisco PIX Firewall 515
- Cisco PIX Firewall 520
References:
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.