CVE-2011-0951
published 2011-04-04CVE-2011-0951: The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to…
PriorityP343medium5CVSS 2.0
AVNACLAuNCNIPAN
EXPLOIT
EPSS
14.64%
96.3th percentile
The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user passwords via unspecified vectors, aka Bug ID CSCtl77440.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is exploited via malicious HTTP requests to the web-based management interface of Cisco Secure ACS; monitor for unexpected or unauthenticated password change requests to the ACS web interface. ↗
- →Exploitation allows arbitrary password change requests for any user in the local/internal identity store without providing the account's previous password; alert on password changes that lack prior-password validation in ACS audit logs. ↗
- →Attackers may require access to internal networks to exploit this vulnerability; restrict external access to the ACS web management interface and monitor for anomalous internal traffic targeting it. ↗
- →Functional exploit code exists (Metasploit module: auxiliary/admin/networking/cisco_secure_acs_bypass); detect use of this module by monitoring for its characteristic request patterns against the ACS management interface. ↗
- ·Only Cisco Secure ACS instances using the internal identity store are vulnerable; accounts defined on external identity stores are not affected. ↗
- ·Vulnerable versions are ACS 5.1 with patches 3, 4, or 5 applied, and ACS 5.2 with no patches or only patches 1 or 2 applied. Fully patched versions (5.1.0.44.6+ and 5.2.0.26.3+) are not vulnerable. ↗
- ·Exploitation is limited to password changes only; an attacker cannot modify access policies, device properties, or any other account attributes. ↗
- ·There is no workaround available for this vulnerability; patching is the only remediation. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Access Control System Password Modification Vulnerability
vendor_cisco·2011-03-30·CVSS 5.0
CVE-2011-0951 [MEDIUM] CWE-287 Cisco Secure Access Control System Password Modification Vulnerability
Cisco Secure Access Control System Password Modification Vulnerability
Cisco Secure Access Control System (ACS) contains a vulnerability that could allow an unauthenticated, remote attacker to modify user passwords.
The vulnerability is due to improper security restrictions on user password change functions in the web-based management interface of the Cisco Secure ACS application. An unauthenticated, remote attacker could exploit this vulnerability by sending malicious requests to the system. If successful, the attacker could modify user account passwords.
Cisco has confirmed this vulnerability in a security advisory and released updated software.
To exploit this vulnerability, an attacker must be able to send malicious requests to the targeted system. Attackers may require access to in
Cisco
Cisco Secure Access Control System Unauthorized Password Change Vulnerability
vendor_cisco
CVE-2011-0951 Cisco Secure Access Control System Unauthorized Password Change Vulnerability
CVE-2011-0951: Cisco Secure Access Control System Unauthorized Password Change Vulnerability
A vulnerability exists in some Cisco Secure Access Control System (ACS) versions that could allow a remote, unauthenticated attacker to change the password of any user account to any value without providing the account's previous password. Successful exploitation requires the user account to be defined on the internal identity store. This vulnerability does not allow an attacker to perform any other changes to the ACS database. That is, an attacker cannot change access policies, device properties, or any account attributes except the user password. Cisco has released software updates that address this vulnerability. There is no workaround for this vulnerability. This advisory is posted at https://s
GHSA
GHSA-4wp6-r9gv-37c2: The web-based management interface in Cisco Secure Access Control System (ACS) 5
ghsa_unreviewed·2022-05-17
CVE-2011-0951 [MEDIUM] GHSA-4wp6-r9gv-37c2: The web-based management interface in Cisco Secure Access Control System (ACS) 5
The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user passwords via unspecified vectors, aka Bug ID CSCtl77440.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/43924http://securitytracker.com/id?1025271http://www.cisco.com/en/US/products/products_security_advisory09186a0080b74117.shtmlhttp://www.securityfocus.com/bid/47093http://www.vupen.com/english/advisories/2011/0821https://exchange.xforce.ibmcloud.com/vulnerabilities/66471http://secunia.com/advisories/43924http://securitytracker.com/id?1025271http://www.cisco.com/en/US/products/products_security_advisory09186a0080b74117.shtmlhttp://www.securityfocus.com/bid/47093http://www.vupen.com/english/advisories/2011/0821https://exchange.xforce.ibmcloud.com/vulnerabilities/66471
2011-04-04
Published