cbcvebase.
CVE-2011-0951
published 2011-04-04

CVE-2011-0951: The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to…

PriorityP343medium5CVSS 2.0
AVNACLAuNCNIPAN
EXPLOIT
EPSS
14.64%
96.3th percentile
The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user passwords via unspecified vectors, aka Bug ID CSCtl77440.

Affected

12 ranges
VendorProductVersion rangeFixed in
ciscosecure
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is exploited via malicious HTTP requests to the web-based management interface of Cisco Secure ACS; monitor for unexpected or unauthenticated password change requests to the ACS web interface.
  • Exploitation allows arbitrary password change requests for any user in the local/internal identity store without providing the account's previous password; alert on password changes that lack prior-password validation in ACS audit logs.
  • Attackers may require access to internal networks to exploit this vulnerability; restrict external access to the ACS web management interface and monitor for anomalous internal traffic targeting it.
  • Functional exploit code exists (Metasploit module: auxiliary/admin/networking/cisco_secure_acs_bypass); detect use of this module by monitoring for its characteristic request patterns against the ACS management interface.
  • ·Only Cisco Secure ACS instances using the internal identity store are vulnerable; accounts defined on external identity stores are not affected.
  • ·Vulnerable versions are ACS 5.1 with patches 3, 4, or 5 applied, and ACS 5.2 with no patches or only patches 1 or 2 applied. Fully patched versions (5.1.0.44.6+ and 5.2.0.26.3+) are not vulnerable.
  • ·Exploitation is limited to password changes only; an attacker cannot modify access policies, device properties, or any other account attributes.
  • ·There is no workaround available for this vulnerability; patching is the only remediation.

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.