Cisco Prime Network Control System Health Monitor Reflected XSS

Apologies for the n00b question,
I am a security manager not a Cisco guru so please bear with me
Our Nessus scanner has picked this vulnerability up
Nessus states that there is no fix
Looking on Cisco's bug search the status is set to fixed, 
https://tools.cisco.com/bugsearch/bug/CSCud18375
I found this article on Cisco's website
Multiple Vulnerabilities in the WLSE Appliance - Cisco 2011-12-10
There are two vulnerabilities that exist in the CiscoWorks Wireless LAN Solution Engine (WLSE). The first is a cross site scripting (XSS) vulnerability that may allow an attacker to gain administrative privileges on the system. The second is a local privilege escalation vulnerability that can be used by an attacker who already has authenticated access to the command line interface to obtain access to the underlying operating system. Cisco has made free software available to address this vulnerability for affected customers. This advisory is available at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20060419-wlse
Is WLSE part of WCS or am I grasping at straws here? Our techies don't seem to think so
We are currently running CISCO Wireless Controller System (WCS) running on Version 7.0.240.0 which is end of life
Is there an upgrade path for newer software?
Has anyone else encountered this issue
http://www.kb.cert.org/vuls/id/830316

1. Its possible but some sort of lock/bug is preventing the removal of the controller. Is the controller reachable? Have you attempted to restart NCS to see if you are able to remove the controller afterwards?
2. 8510 not supported on NCS, you must upgrade to Cisco Prime 1.3.x or higher.
http://www.cisco.com/en/US/docs/net_mgmt/prime/infrastructure/1.3/release/notes/cpi_rn_13.html#wp86690
3.  Follow the upgrade steps for all information regarding patches and migration path:
http://www.cisco.com/en/US/docs/wireless/prime_infrastructure/1.3/quickstart/guide/cpi_qsg_1_3.html#wp69624

Similar Messages

  • Cisco Prime Infrastructure 1.2 with Cisco Prime Network Control System Hardware Appliance

    Hi Team,
    I have  following BOM
    Cisco Prime Infrastructure
    R-PI-1.2-K9
    Cisco Prime Infrastructure 1.2
    1
    R-PI-1.1-500-K9
    Prime Infrastructure 1.2 Software - 500 Device Base Lic
    1
    L-PILMS42-500
    Prime Infrastructure LMS 4.2 - 500 Device Base Lic
    1
    L-PINCS12-500
    Prime Infrastructure NCS 1.2 - 500 Device Base Lic
    1
    PRIME-NCS-APL-K9
    Cisco Prime Network Control System Hardware Appliance
    1
    PI-APL-IMAGE-1.2
    Cisco Prime Infrastructure 1.2 Appliance Software
    1
    Pls let me know if we have both NCS and LMS preinstalled with Cisco Prime Infrastructure 1.2 Appliance Software orwe need seperate appliance or server for LMS 4.2. 
    Regards

    Hi Scott,
    Thanks for the response but I got to know that LMS and NCS are combined in single ISO image from PI 1.2 and can be installed on the same physical NCS appliance.
    Can you pls check this.
    Regards

  • Cisco Prime Network Control System (NCS) - Reports

    Hiya Supporters !
    Just wonder how to make a report showing me which AP's in my setup that NEVER have any associated clients on, and/or over a given period of time, like 1 or months.
    seems like I can get some reports under :
    reports - report launch pad - clients
    but i can not get clients count = 0 by "AP name"
    anyone know how ?
    I use WLC's versions 7.0.116 and NCS 1.0.2.29 appliance on ESX

    mbilgrav,
    There is a command on the NCS CLI that looks interesting:
    # ncs db reinitdb
    wilab-ncs/admin# ncs db ?  reinitdb  Reinitialize NCS database by dropping all the tables
    DISCLAIMER: I'm not a database guy, I've never used this command, and I have no idea what the ramifications are (I've searched and haven't found much). If you do decide to try it, snapshot/backup first and proceed at your own risk.
    UPDATE: Curiousity got the best of me and I ran this command on my own lab NCS. I can confirm that this wipes out the NCS database completely and dumps you back to defaults. All user accounts except root are deleted, along with maps, devices and settings. The only thing that appears to be preserved is licensing. So... this could be useful if you wanted to re-attempt a WCS database migration: You could delete the offending AP entry within WCS first, then migrate your db over to NCS and presumably it would import without this AP record. That's assuming you came over from WCS in the first place, which I don't think you mentioned.
    Other than that, you could try TAC. It sounds like a corrupt database entry or a bug to me, so maybe they can give you a sql query that will clear it out from the CLI or something.
    If it were my system, I would snapshot/backup the 1.0 installation and then upgrade to 1.1. If you don't like the upgrade or if it breaks anything, you can restore your 1.0 snapshot.
    Please let us know if/how you are able to resolve the issue.
    Justin

  • Prime network control system appliance (NCS)

    Hi,
    i have a new cisco prime network control system appliance (NCS)
    I completed the initial installation however post installation it performed a reboot and is now stuck at Init Level 3.
    I have restarted the machine several time but the same result.

    Umm a new appliance should have had the application pre-installed. Were you upgrading?
    In either case, you'll probably need to open a TAC case. Even without Smartnet you should have at least 90-day warranty support

  • Cisco Network Control System software

    As far as I know, the NCS is an appliance. But today some people told me that he has a copy of Cisco's Network Control System software. I am confused. If what he said is true, can I install the software on the Windows platforms like Win2003 or Win2008?
    Thanks in advance.
    Robert

    Hi Robert,
    Here we go
    Product Specifications for Cisco Prime NCS
    Item
    Specification
    VMware ESX and ESXi Versions (Virtual Appliance on a Customer-Supplied Server)
    If deploying Cisco Prime NCS as a virtual appliance, on a customer-supplied server, one of the following versions of VMware ESX or ESXi may be used:
    • VMWare ESX or VMWare ESXi version 4.1
    Minimum Server Requirements for Deploying Virtual Appliances
    Cisco Prime NCS High-End Virtual Appliance:
    • 15,000 lightweight access points; 5000 standalone access points; 1200 wireless LAN controllers and 5000 switches
    • Minimum RAM: 16GB
    • Minimum Hard disk space allocation: 400GB
    • Processors: 8, at 2.93GHz or better
    Cisco Prime NCS Standard Virtual Appliance:
    • 7500 lightweight access points; 2500 standalone access points; 600 wireless LAN controllers and 2500 switches
    • Minimum RAM: 12GB
    • Minimum Hard disk space allocation: 300GB
    • Processors: 4, at 2.93GHz or better
    Cisco Prime NCS Low-End Virtual Appliance:
    • 3000 lightweight access points; 1000 standalone access points; 240 wireless LAN controllers and 1000 switches
    • Minimum RAM: 8GB
    • Minimum Hard disk space allocation: 200GB
    • Processors: 2, at 2.93GHz or better
    Deploying Cisco Prime NCS Virtual Appliance on CiscoWorks Wireless LAN Solution Engine (WLSE) models 1130-19 or 1133
    • Cisco Prime NCS is not supported on the Cisco WLSE hardware
    http://www.cisco.com/en/US/prod/collateral/wireless/ps5755/ps11682/ps11686/ps11688/data_sheet_c78-650051.html
    Cheers!
    Rob

  • Ask The Expert: Understanding, Implementing, and Troubleshooting Cisco Prime Network

    Ask questions and learn about Cisco Prime Network with Cisco experts Vignesh Rajendran Praveen and Jaminder Singh Bali.
    Cisco Prime Network is and  Cisco Prime Network provides cost-effective device operation, administration and network fault management for today’s complex and evolved programmable networks (EPNs). It is a single solution to support both the traditional physical network components, as well as compute infrastructure, and the virtual elements found in data centers. Automated configuration and change management combined with advanced troubleshooting and diagnostics greatly help service providers enable proactive service assurance. Additionally, the flexible and extensible architecture is designed to support the multivendor environment, helping to lower operational costs.
    This event runs January 5 through January 16, 2015.
    Vignesh Rajendran Praveen is a High Touch Engineer with the Focused Technical Services team supporting Cisco's major Service Provider customers in Routing, Switching, Multiprotocol Label Switching (MPLS) technologies and Cisco Prime Network related issues. Previously at Cisco he has worked as a Network Consulting Engineer for Enterprise Customers and as a Customer Support Engineer for Service Provider customers. He has been in the networking industry for ten years and holds CCIE certification (#34503) in the Routing and Switching as well as Service Provider tracks.
    Jaminder Singh Bali is a Customer Support Engineer working in SP-NMS TAC team, supporting Cisco's major service provider customers in Cisco Prime Network, Performance and Prime Central related issues. His areas of expertise include Oracle, Linux and NMS applications. He has been in the industry for past six years.
    Remember to use the rating system to let the experts know if you have received an adequate response. 
    The Experts might not be able to answer each question due to the volume expected during this event. Remember that you can continue the conversation in Network Infrastructure community, sub-community, LAN, Switching and Routing discussion forum shortly after the event. This event lasts through January 16, 2015. Visit this forum often to view responses to your questions and the questions of other community members.

    Hello Jerome,
    A variety of Cisco devices are supported by the the Cisco Prime Network. I would encourage you to go through the below links on the user guide depending the version of Cisco Prime Network being used.
    "Cisco Prime Network Supported Cisco Virtual Network Elements (VNEs)"
    "Cisco Prime Network Supported Cisco VNEs - Addendum"
    Below is the link for the user guide.
    http://www.cisco.com/c/en/us/support/cloud-systems-management/prime-network/products-user-guide-list.html
    Hope this would help in providing you more clarity.
    ***********Plz do rate this post if you found it helpful*************************
    Thanks & Regards,
    Vignesh R P

  • Administration Utilities - System Health Monitor - alui 6.1

    I'm curious if there is a way I can turn the System Health Monitor utility into a portlet?
    It seems like there should an easy way to do this, but I can't seem to find it. Any insight you might be able to provide on either the System Health Monitor or the administration utilities. Or anything that might help for that matter, would be be most appreciated.
    Thanks,
    -Kevin

    Hi geoffgarcia, thanks for looking into my question. I have tried to pass the existing URL back in, as you have suggested, but with no luck. For example:
    > Create new Web Service : URL : http://[MYPORTALSERVER]/portal/server.pt?open=space&name=diagnostic&psname=ObjMgr&psid=3&cached=true&control=EditorStart&editorType=10
    and then generate a portlet to that service. When I add that portlet to my homepage it throws a
    "Error      Error - The server has experienced an error. Try again or contact your portal administrator if you continue experiencing problems."
    error, but doesn't log the error. View source shows the error to be
    "Current User does not have sufficient permission to object with id = 52: com.plumtree.server.marshalers.PTException.... blah blah blah...."
    Any ideas? Maybe I'm missing a glaringly obvious setting/configuration?
    Thanks again,
    -Kevin

  • Cisco Prime network and cisco prime infrastructure

    Hi,
    What is the difference between Cisco Prime Network and Cisco Prime infrastructure.
    Please advice.

    I assume you are asking about Cisco Prime LAN Management System (LMS) vs. Cisco Prime Infrastructure (PI).
    LMS is currently the leading Cisco offering for wired infrastructure management. It is the evolution of the earlier CiscoWorks LMS, CiscoWorks RWAN CiscoWorks 2000, CWSI, VLAN Director, original CiscoWorks classic etc. products going back almost 20 years.
    PI is the equivalent Cisco offering for wireless LANs and is the successor to NCS and WCS products.
    The overlap and confusion comes from the fact the Cisco is positioning PI as the overall wireless and wired management platform and gradually introducing wired network management features to make it equal (and eventually exceed) LMS's capabilities.
    There is a comparison table here that shows the current differences. A major new release of PI (2.0) is due out shortly which will close many (but not all) of the gaps on that table.

  • Cisco Prime Network 4.0

    Hi,          
    Has someone installed Cisco Prime Network on another distribution than Redhat ? I want to install a local demo and I have only RedHat trial.
    What is the optimal mode of installation Prime Network ? Unit  + GW and DB on the same machine? I would like to install in the same machine, but
    I´m not sure if it will run ok.
    If this is the optimal assembly mode, which is the required bandwidth between  Unit, Gw and DB.?
    Thanks.
    Regards.

    I found the solution is to restart network control services in Prime Network and restart control services in Prime Central from the Linux OS

  • Ask the Expert:Cisco Prime Network Registrar

    With Pete Newcomb & Jim Brown 
    Welcome to the Cisco Support Community Ask the Expert conversation. Learn from experts Peter Newcomb and Jim Brown about  Cisco Prime Network Registrar, Cisco's industry leading solution for integrated DNS, DHCP and  IP address management (IPAM) services  for both IPv4 and IPv6. 
    Pete Newcomb is a technical marketing engineer in Cisco's Network Management and Technology Group and has over 30 years of experience in the voice and data communications industry, including sales support and product engineering support with several companies. His design and development background includes wireless services, switching, routing, TCP/IP, Frame Relay, X.25, telephony services, risk management, and network security. 
    Jim Brown is a customer support  engineer in Cisco's Network Management and Technology Group. He has over 35 years of experience in development engineering and customer service, real-time and fault tolerant operating systems, and network management for the telecommunications and software industries. For the last 14 years he has been with the Network Registrar Development Team, interfacing with Customer Service and directly with customers in problem solving.
    Remember to use the rating system to let Pete and Jim know if you have received an adequate response.  
    Pete and Jim might not be able to answer each question due to the volume expected during this event. Remember that you can continue the conversation on the Network Infrastructure sub-community   forum shortly after the event. This event lasts through January 18, 2013. Visit this forum often to view responses to your questions and the questions of other community members.

    Hi Jorge,
       Absolutely, Prime CNR supports IPv6 since CNR 6.x versions...
       For IPv6 configuration instructions on latest versions of CPNR you should start here;
          http://www.cisco.com/en/US/partner/docs/net_mgmt/prime/network_registrar/8.1/user/guide/UG25_IP6.html
                                                        Best Regards
                                                        Jim Brown

  • Cisco prime network repository image asr903

    I'm having an issue with Cisco Prime Network Repository Images getting image from ASR903 devices.
    I am only obtaining the packages.conf file (bootvar is configured to boot from that file (boot system flash bootflash:issu/packages.conf)).
    Any idea in order to get the correct image?
    Thanks a lot and best regards,

    Hi Scott,
    Thanks for the response but I got to know that LMS and NCS are combined in single ISO image from PI 1.2 and can be installed on the same physical NCS appliance.
    Can you pls check this.
    Regards

  • Link does not work for-End-of-Sale and End-of-Life Announcement for the Cisco Secure Access Control System 5.4

    Link does not work for
    End-of-Sale and End-of-Life Announcement for the Cisco Secure Access Control System 5.4
    How do we get Cisco to fix?
    see attachment

    Give it a couple of days - it looks like they just sent out the notification before the notice was published on the public page.
    Once the ACS 5.4 EoS/EoL notice is published you should see it linked from this page.

  • Network Control System - one device for whole world?

    Hi all,
    we have Network Control System located in South Africa. Would it be possible to effectively use it also for devices in e.g. LATAM, Europe or Australia? Round Trip Time for these locations can be up to 500 ms, ocassionaly, during busy hours, this can go up to 800 ms.
    Thanks,
    Gorazd

    Hi Scott,
    Thanks for the response but I got to know that LMS and NCS are combined in single ISO image from PI 1.2 and can be installed on the same physical NCS appliance.
    Can you pls check this.
    Regards

  • Daily System Health monitoring report from SOLMAN

    Hi Experts,
    I am working on a project where I need to triiger a consolidated system health report from sol man, much like early watch report.
    Only thing is that it should be generated daily for each system.
    Well That makes the expectation.
    Progress so far :-
         a. Applied E2E120 for managed system ie Technical monitoring is working for that system.
    Challenge :-
       a. Generating a consolidated report, with checklists for system logs, dumps, qrfc / trfc's. As Technical monitoring is giving these info separately.
       b. Options in technical monitoring are too many and not sure which can deliver what i am looking for.
              a. IT Performance reporting
              b. Service level reporting
              c. SDCCN Reporting.
              d. or automatic configure reporting.
       c. The report has to be generated periodically only once in a day. It should not be alert monitoring that an system alert triggers a mail and management is bombarded with too many mails.
    Any valuable suggestion will be very helpful and will certainly be rewarded.
    Thanks
    Abhijeet

    Hi Jhansi,
    few things first, I have really liked your blogs and forum discussion on Sol Man. They have been really very helpful.
    Now, after spending around 2-3 days on it, Closest bet is  "IT Performance reporting". With this i am compromising with consolidated report. (Just hoping management agrees for it )
    But here is the new challenge I am going through. It is the web templates to use for specific checklist.
    I used below link.
    http://help.sap.de/saphelp_sm71_sp05/helpdata/en/3f/ecbef23769488f806177717adee541/content.htm?frameset=/en/a3/074aa01bbe4662b99bc20ec5263cf8/frameset.htm&current_toc=/en/81/6f8fe54f854ef2bd412c8660f5ed6e/plain.htm&node_id=463
    I need template for System logs, qrfc, trfc, PI messages etc. It is not present in the link provided. Even searched on SMP, it was not available. Can we manually create and use the web templates.
    Also when i used such templates, I am getting following error message in the monitoring
    Let me know your inputs.
    Thanks
    Abhijeet

  • Cisco Prime Infrastructure Operating System

    I need some help here. I know that Prime Infrasturcture virtual appliance deployments are ESX and ESXi, but do I need to have Red Hat Linux Enterprise Server 5.4 64-bit also? This is getting confusing.
    Thanks.
    Todd Kelly

    Like Seth said it's all included in the ova distributions. Both PI and Prime LMS ova's bundle Cisco's "ADE-OS" Application Development Environment Operating System - a RHEL build.
    PI doesn't let you access the root shell but here's exactly what's included in LMS, for example:
    [SecLab-LMS/root-ade ~]# uname -a
    Linux SecLab-LMS 2.6.18-238.1.1.el5 #1 SMP Tue Jan 4 13:32:19 EST 2011 x86_64 x86_64 x86_64 GNU/Linux
    [SecLab-LMS/root-ade ~]#
    [SecLab-LMS/root-ade ~]# cat /etc/*-release
    ##############CARS build log for cars20-rhel-x86_64##############
    Date: Mon Feb 28 20:06:05 PST 2011
    Builder: pmbure
    Project: cars20-rhel-x86_64
    Branch: trunk
    Build Version: 2.0.1.021
    Build Server: aons-build5
    Destination: /auto/johann/linux/kickstarts/cars20-rhel-x86_64//CARS_2.0.1.021_cars20-rhel-x86_64_022811_2006/2.0.1.021
    Log File: /auto/johann/linux/kickstarts/cars20-rhel-x86_64//logs/CARS_2.0.1.021_cars20-rhel-x86_64_022811_2006.log
    Local Arch: x86_64
    Distro Vendor: rhel
    Using master kickstart import file: /auto/perseus/BRANCHES/meta/trunk/ks_import_rhel_x86_64.cfg
    Partitioning scheme: /auto/perseus/etc/templates/smos30.part
    Red Hat Enterprise Linux Server release 5.4 (Tikanga)
    [SecLab-LMS/root-ade ~]#

Maybe you are looking for

  • ARV_BC_XMB_DEL Fails With Raise Exception

    Hi All,     I have scheduled the archiving job in PI 7.0 through sxmb_adm -> Schedule Archiving.     After scheduling I can see two jobs successfully released             1. ARV_BC_XMB_DEL - This job uses the program "RSXMB_DELETE_ARCHIVED_MESSAGES"

  • NTP Log Errors

    So I just installed NTP on my server and verified everything is working as expected and please keep in mind I am very green w/ systemd: [root@ion101 ~]# systemctl status ntpd.service ● ntpd.service - Network Time Service Loaded: loaded (/usr/lib/syst

  • Messages can't communicate with the account "AIM." Cannot log in to AIM. General error. Try again

    Hi, For the first time today, I've been having problems connecting to AIM using Messages. I get the "Messages can't communicate with the account "AIM." Cannot log in to AIM. General error. Try again." error. I looked at the forums here and I tried de

  • TS4083 Email Syncing Between Devices

    I am having the opposite issue. When I read an email on my macbook the email appears read on the ipad and iphone. But if I read it on my iphone and ipad, it does not appear read on my mac. All are synced with my icloud account. Any thoughts??

  • Windows 8 PRO - Notebook HP 620

    Hi, I installed windows 8 PRO original site purchased by Microsoft, on my notebook HP 620. All the drivers are fine, but no sound is heard. The audio driver is installed correctly, but you do not hear. There is a beta download for the HP 620? Thanks