CVE-2002-0159
Severity
7.5HIGH
EPSS
2.3%
top 15.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 22
Latest updateApr 30
Description
Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages1 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-gjqp-7xq4-7mr3: Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2↗2022-04-30
CVEList▶
CVE-2002-0159: Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2↗2002-06-25