CVE-2014-0648Improper Input Validation in Cisco Secure Access Control System

Severity
10.0CRITICALNVD
EPSS
7.8%
top 8.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16
Latest updateMay 17

Description

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements, which allows remote attackers to obtain administrative access via a request to this interface, aka Bug ID CSCud75187.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-r5wc-p8jh-hvf4: The RMI interface in Cisco Secure Access Control System (ACS) 52022-05-17
CVEList
CVE-2014-0648: The RMI interface in Cisco Secure Access Control System (ACS) 52014-01-16

📋Vendor Advisories

1
Cisco
Multiple Vulnerabilities in Cisco Secure Access Control System2014-01-16
CVE-2014-0648 — Improper Input Validation in Cisco | cvebase