CVE-2014-0648
published 2014-01-16CVE-2014-0648: The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements, which…
PriorityP259critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.93%
92.4th percentile
The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements, which allows remote attackers to obtain administrative access via a request to this interface, aka Bug ID CSCud75187.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_system | <= 5.4.0.46.6 | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
| cisco | secure_access_control_system | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated or anomalous inbound connections to TCP ports 2020 and 2030 (Cisco ACS RMI interface) from hosts that are not legitimate ACS cluster nodes, as exploitation involves sending crafted requests to the RMI interface to gain administrative access without valid credentials. ↗
- →Restrict access to TCP ports 2020 and 2030 at the network perimeter to only known ACS internode communication peers; unexpected external sources connecting to these ports are a strong indicator of exploitation attempts. ↗
- ·The RMI vulnerabilities (CVE-2014-0648 and related) are independent of each other; a release affected by one may not be affected by the other. Verify which specific vulnerability applies to the deployed ACS version before scoping detection. ↗
- ·The vulnerable attack surface is the RMI interface used for internode (cluster) communication; deployments where ACS nodes are not clustered or where RMI ports are already firewalled off from untrusted networks have reduced exposure. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Secure Access Control System
vendor_cisco·2014-01-16·CVSS 8.5
CVE-2014-0648 [HIGH] CWE-20 Multiple Vulnerabilities in Cisco Secure Access Control System
Multiple Vulnerabilities in Cisco Secure Access Control System
Cisco Secure Access Control System (ACS) is affected by the following vulnerabilities:
Cisco Secure ACS RMI Privilege Escalation Vulernability
Cisco Secure ACS RMI Unauthenticated User Access Vulnerability
Cisco Secure ACS Operating System Command Injection Vulnerability
Cisco Secure ACS uses the Remote Method Invocation (RMI) interface for internode communication using TCP ports 2020 and 2030.
These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the other.
Cisco has released software updates that address these vulnerabilities. This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecur
Cisco
Multiple Vulnerabilities in Cisco Secure Access Control System
vendor_cisco
CVE-2014-0648 Multiple Vulnerabilities in Cisco Secure Access Control System
CVE-2014-0648: Multiple Vulnerabilities in Cisco Secure Access Control System
Cisco Secure Access Control System (ACS) is affected by the following vulnerabilities: Cisco Secure ACS RMI Privilege Escalation Vulernability Cisco Secure ACS RMI Unauthenticated User Access Vulnerability Cisco Secure ACS Operating System Command Injection Vulnerability Cisco Secure ACS uses the Remote Method Invocation (RMI) interface for internode communication using TCP ports 2020 and 2030. These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the other. Cisco has released software updates that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/Ci
GHSA
GHSA-r5wc-p8jh-hvf4: The RMI interface in Cisco Secure Access Control System (ACS) 5
ghsa_unreviewed·2022-05-17
CVE-2014-0648 [HIGH] GHSA-r5wc-p8jh-hvf4: The RMI interface in Cisco Secure Access Control System (ACS) 5
The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements, which allows remote attackers to obtain administrative access via a request to this interface, aka Bug ID CSCud75187.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/102117http://secunia.com/advisories/56213http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140115-csacshttp://tools.cisco.com/security/center/viewAlert.x?alertId=32379http://www.securityfocus.com/bid/64962http://www.securitytracker.com/id/1029634https://exchange.xforce.ibmcloud.com/vulnerabilities/90431http://osvdb.org/102117http://secunia.com/advisories/56213http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140115-csacshttp://tools.cisco.com/security/center/viewAlert.x?alertId=32379http://www.securityfocus.com/bid/64962http://www.securitytracker.com/id/1029634https://exchange.xforce.ibmcloud.com/vulnerabilities/90431
2014-01-16
Published