CVE-2002-0159

Severity
7.5HIGH
EPSS
2.3%
top 15.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateApr 30

Description

Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gjqp-7xq4-7mr3: Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 22022-04-30
CVEList
CVE-2002-0159: Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 22002-06-25

📋Vendor Advisories

1
Cisco
Web Interface Vulnerabilities in Cisco Secure ACS for Windows2002-04-03
CVE-2002-0159 (HIGH CVSS 7.5) | Format string vulnerability in the | cvebase.io