CVE-2004-1461
published 2004-12-31CVE-2004-1461: Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the…
PriorityP337high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.68%
74.2th percentile
Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Secure Access Control Server
vendor_cisco·2004-08-25
CVE-2004-1458 Multiple Vulnerabilities in Cisco Secure Access Control Server
Multiple Vulnerabilities in Cisco Secure Access Control Server
Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco
Secure Access Control Server Solution Engine (ACS Solution Engine) provide
authentication, authorization, and accounting (AAA) services to network devices
such as a network access server, Cisco PIX and a router. This advisory
documents multiple Denial of Service (DoS) and authentication related
vulnerabilities for the ACS Windows and the ACS Solution Engine servers.
The vulnerabilities are documented as these Cisco bug IDs:
CSCeb60017
(
registered customers only)
CSCec66913
(
registered customers only)
CSCec90317
(
registered customers only)
CSCed81716
(
registered customers only)
CSCef05950
(
registered customers only)
This advisory wil
Cisco
Multiple Vulnerabilities in Cisco Secure Access Control Server
vendor_cisco
CVE-2004-1461 Multiple Vulnerabilities in Cisco Secure Access Control Server
CVE-2004-1461: Multiple Vulnerabilities in Cisco Secure Access Control Server
Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) provide authentication, authorization, and accounting (AAA) services to network devices such as a network access server, Cisco PIX and a router. This advisory documents multiple Denial of Service (DoS) and authentication related vulnerabilities for the ACS Windows and the ACS Solution Engine servers. The vulnerabilities are documented as these Cisco bug IDs: CSCeb60017 ( registered customers only ) CSCec66913 ( registered customers only ) CSCec90317 ( registered customers only ) CSCed81716 ( registered customers only ) CSCef05950 ( registered customers only ) This advisory will
GHSA
GHSA-5224-x825-p35j: Cisco Secure Access Control Server (ACS) 3
ghsa_unreviewed·2022-04-29
CVE-2004-1461 [HIGH] GHSA-5224-x825-p35j: Cisco Secure Access Control Server (ACS) 3
Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.
No detection rules found.
No writeups or analysis indexed.
http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtmlhttp://www.securityfocus.com/bid/11047https://exchange.xforce.ibmcloud.com/vulnerabilities/17118http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtmlhttp://www.securityfocus.com/bid/11047https://exchange.xforce.ibmcloud.com/vulnerabilities/17118
2004-12-31
Published