CVE-2002-0241
published 2002-05-29CVE-2002-0241: NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services…
PriorityP425high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.62%
73.3th percentile
NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fc5v-r7j2-4w95: NDSAuth
ghsa_unreviewed·2022-04-30
CVE-2002-0241 [HIGH] GHSA-fc5v-r7j2-4w95: NDSAuth
NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.
Cisco
Cisco Secure Access Control Server Novell Directory Service Expired/Disabled User Authentication Vulnerability
vendor_cisco·2002-02-07
CVE-2002-0241 Cisco Secure Access Control Server Novell Directory Service Expired/Disabled User Authentication Vulnerability
Cisco Secure Access Control Server Novell Directory Service Expired/Disabled User Authentication Vulnerability
Specific versions of Cisco Secure Authentication Control Server (ACS)
allows authentication of users that have been explicitly disabled or expired in
the Novell Directory Services (NDS). There is a software patch that may be
applied, and software upgrades will also address this problem.
The complete notice will be available at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020207-acs-nds-auth.
Cisco
Cisco Secure Access Control Server Novell Directory Service Expired/Disabled User Authentication Vulnerability
vendor_cisco
CVE-2002-0241 Cisco Secure Access Control Server Novell Directory Service Expired/Disabled User Authentication Vulnerability
CVE-2002-0241: Cisco Secure Access Control Server Novell Directory Service Expired/Disabled User Authentication Vulnerability
Specific versions of Cisco Secure Authentication Control Server (ACS) allows authentication of users that have been explicitly disabled or expired in the Novell Directory Services (NDS). There is a software patch that may be applied, and software upgrades will also address this problem. The complete notice will be available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020207-acs-nds-auth .
Bug IDs: CSCdw46931, CSCdw46931
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/warp/public/707/ciscosecure-acs-nds-authentication-vuln-pub.shtmlhttp://www.iss.net/security_center/static/8106.phphttp://www.securityfocus.com/bid/4048http://www.cisco.com/warp/public/707/ciscosecure-acs-nds-authentication-vuln-pub.shtmlhttp://www.iss.net/security_center/static/8106.phphttp://www.securityfocus.com/bid/4048
2002-05-29
Published