CVE-2000-1056

4 documents4 sources
Severity
7.5HIGH
EPSS
0.5%
top 33.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateApr 30

Description

CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDcisco/secure_access_control_server2.1, 2.3\(3\), 2.4\(2\)+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5rvg-rpvg-3vmc: CiscoSecure ACS Server 22022-04-30
CVEList
CVE-2000-1056: CiscoSecure ACS Server 22001-01-22

💥Exploits & PoCs

1
Exploit-DB
Atrium Software Mercur WebView WebMail-Client 1.0 - Buffer Overflow2000-03-16
CVE-2000-1056 (HIGH CVSS 7.5) | CiscoSecure ACS Server 2.4(2) and e | cvebase.io