Cisco - Cisco NAC Can't Keep a Secret - eWeek Security Watch

Cisco NAC Can’t Keep a Secret

Written By
Ryan Naraine
Ryan Naraine
Apr 18, 2008
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A serious security flaw in the Cisco NAC (Network Admission Control) appliance can allow an attacker to obtain the shared secret that is used between the two internal components, according to a warning from the network and switching vendor.

The vulnerability, which carries a CVSS base score of 10.0 (the highest possible severity rating), could be exploited to allow an attacker to “take complete control” of the Cisco NAC appliance remotely over the network.

From the Cisco advisory:

“The Cisco NAC Appliance solution allows network administrators to authenticate, authorize, evaluate, and remediate wired, wireless, and remote users and their machines prior to allowing users onto the network. The solution identifies whether machines are compliant with security policies and repairs vulnerabilities before permitting access to the network.A vulnerability exists in the Cisco NAC Appliance that can allow an attacker to obtain the shared secret used by the CAS and the CAM from error logs that are transmitted over the network. Obtaining this information could enable an attacker to gain complete control of the CAS remotely over the network.“

Despite the high-risk rating, WatchGuard’s Corey Nachreiner says there is one mitigating factor that significantly lessens its risk in the real world:

“In most networks, data transmitted from the CAS to the CAM only passes over a Local Area Network (LAN). This means an attacker needs local access to your internal network in order to sniff the traffic necessary to learn your CAS shared secret and carry out this attack. So you can consider this primarily an insider threat.“

Nevertheless, Cisco’s NAC appliance users should apply this patch as a matter of urgency.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.