cbcvebase.
CVE-2014-0648
published 2014-01-16

CVE-2014-0648: The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements, which…

PriorityP259critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.93%
92.4th percentile
The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements, which allows remote attackers to obtain administrative access via a request to this interface, aka Bug ID CSCud75187.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
ciscosecure
ciscosecure_access_control_system<= 5.4.0.46.6
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system
ciscosecure_access_control_system

Detection & IOCsextracted from sources · hover to see the quote

portTCP/2020
portTCP/2030
  • Monitor for unauthenticated or anomalous inbound connections to TCP ports 2020 and 2030 (Cisco ACS RMI interface) from hosts that are not legitimate ACS cluster nodes, as exploitation involves sending crafted requests to the RMI interface to gain administrative access without valid credentials.
  • Restrict access to TCP ports 2020 and 2030 at the network perimeter to only known ACS internode communication peers; unexpected external sources connecting to these ports are a strong indicator of exploitation attempts.
  • ·The RMI vulnerabilities (CVE-2014-0648 and related) are independent of each other; a release affected by one may not be affected by the other. Verify which specific vulnerability applies to the deployed ACS version before scoping detection.
  • ·The vulnerable attack surface is the RMI interface used for internode (cluster) communication; deployments where ACS nodes are not clustered or where RMI ports are already firewalled off from untrusted networks have reduced exposure.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco8.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.