CVE-2002-0159
published 2002-04-22CVE-2002-0159: Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.44%
91.8th percentile
Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_acs_for_windows | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gjqp-7xq4-7mr3: Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2
ghsa_unreviewed·2022-04-30
CVE-2002-0159 [HIGH] CWE-134 GHSA-gjqp-7xq4-7mr3: Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2
Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002.
Cisco
Web Interface Vulnerabilities in Cisco Secure ACS for Windows
vendor_cisco·2002-04-03
CVE-2002-0159 Web Interface Vulnerabilities in Cisco Secure ACS for Windows
Web Interface Vulnerabilities in Cisco Secure ACS for Windows
Cisco Secure Access Control Server (ACS) for Windows contains two
vulnerabilities. One vulnerability can lead to the execution of an arbitrary
code on an ACS server, and the second can lead to an unauthorized disclosure of
information. A patch is available for both vulnerabilities.
Cisco Secure ACS for Unix is not vulnerable. No other Cisco product is
vulnerable.
There is no direct workaround for the vulnerabilities, but it is
possible to mitigate them to a great extent. See the
Workarounds section for details.
This advisory is available at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020403-acs-win-web.
Cisco
Web Interface Vulnerabilities in Cisco Secure ACS for Windows
vendor_cisco
CVE-2002-0159 Web Interface Vulnerabilities in Cisco Secure ACS for Windows
CVE-2002-0159: Web Interface Vulnerabilities in Cisco Secure ACS for Windows
Cisco Secure Access Control Server (ACS) for Windows contains two vulnerabilities. One vulnerability can lead to the execution of an arbitrary code on an ACS server, and the second can lead to an unauthorized disclosure of information. A patch is available for both vulnerabilities. Cisco Secure ACS for Unix is not vulnerable. No other Cisco product is vulnerable. There is no direct workaround for the vulnerabilities, but it is possible to mitigate them to a great extent. See the
Bug IDs: CSCdx17622, CSCdx17683, CSCdx17689, CSCdx17698
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=101787248913611&w=2http://www.cisco.com/warp/public/707/ACS-Win-Web.shtmlhttp://www.iss.net/security_center/static/8742.phphttp://www.osvdb.org/2062http://www.securityfocus.com/bid/4416http://marc.info/?l=bugtraq&m=101787248913611&w=2http://www.cisco.com/warp/public/707/ACS-Win-Web.shtmlhttp://www.iss.net/security_center/static/8742.phphttp://www.osvdb.org/2062http://www.securityfocus.com/bid/4416
2002-04-22
Published