CVE-2015-0580
published 2015-02-12CVE-2015-0580: Multiple SQL injection vulnerabilities in the ACS View reporting interface pages in Cisco Secure Access Control System (ACS) before 5.5 patch 7 allow remote…
PriorityP339medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
0.92%
56.1th percentile
Multiple SQL injection vulnerabilities in the ACS View reporting interface pages in Cisco Secure Access Control System (ACS) before 5.5 patch 7 allow remote authenticated administrators to execute arbitrary SQL commands via crafted HTTPS requests, aka Bug ID CSCuq79027.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_system | <= 5.5.0.46 | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Access Control System SQL Injection Vulnerability
vendor_cisco·2015-02-11·CVSS 9.0
CVE-2015-0580 [CRITICAL] CWE-89 Cisco Secure Access Control System SQL Injection Vulnerability
Cisco Secure Access Control System SQL Injection Vulnerability
Cisco Secure Access Control System (ACS) prior to version 5.5 patch 8 is vulnerable to a SQL injection
attack in the ACS View reporting interface pages. A
successful attack could allow an authenticated, remote attacker to access and modify information such as RADIUS accounting records stored in one of the ACS View databases or to access information in the underlying file system. A previous version of this advisory indicated that a product running version 5.5 patch 7 was not vulnerable; however, customers running version 5.5 patch 7 should upgrade to patch 8 to completely mitigate the vulnerability described in this advisory.
Cisco has released software updates that address this vulnerability.
This advisory is available at
Cisco
Cisco Secure Access Control System SQL Injection Vulnerability
vendor_cisco
CVE-2015-0580 Cisco Secure Access Control System SQL Injection Vulnerability
CVE-2015-0580: Cisco Secure Access Control System SQL Injection Vulnerability
Cisco Secure Access Control System (ACS) prior to version 5.5 patch 8 is vulnerable to a SQL injection attack in the ACS View reporting interface pages. A successful attack could allow an authenticated, remote attacker to access and modify information such as RADIUS accounting records stored in one of the ACS View databases or to access information in the underlying file system. A previous version of this advisory indicated that a product running version 5.5 patch 7 was not vulnerable; however, customers running version 5.5 patch 7 should upgrade to patch 8 to completely mitigate the vulnerability described in this advisory. Cisco has released software updates that address this vulnerability. This advisory is ava
GHSA
GHSA-cfgg-h2rv-pf7x: Multiple SQL injection vulnerabilities in the ACS View reporting interface pages in Cisco Secure Access Control System (ACS) before 5
ghsa_unreviewed·2022-05-17
CVE-2015-0580 [MEDIUM] CWE-89 GHSA-cfgg-h2rv-pf7x: Multiple SQL injection vulnerabilities in the ACS View reporting interface pages in Cisco Secure Access Control System (ACS) before 5
Multiple SQL injection vulnerabilities in the ACS View reporting interface pages in Cisco Secure Access Control System (ACS) before 5.5 patch 7 allow remote authenticated administrators to execute arbitrary SQL commands via crafted HTTPS requests, aka Bug ID CSCuq79027.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150211-csacshttp://www.securityfocus.com/bid/72576http://www.securitytracker.com/id/1031740https://exchange.xforce.ibmcloud.com/vulnerabilities/100812http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150211-csacshttp://www.securityfocus.com/bid/72576http://www.securitytracker.com/id/1031740https://exchange.xforce.ibmcloud.com/vulnerabilities/100812
2015-02-12
Published