CVE-2017-3841
published 2017-02-22CVE-2017-3841: A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensitive…
PriorityP346high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.40%
82.1th percentile
A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensitive information. More Information: CSCvc04854. Known Affected Releases: 5.8(2.5).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_system | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wf22-79v6-f4wh: A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensi
ghsa_unreviewed·2022-05-17
CVE-2017-3841 [HIGH] CWE-200 GHSA-wf22-79v6-f4wh: A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensi
A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensitive information. More Information: CSCvc04854. Known Affected Releases: 5.8(2.5).
Cisco
Cisco Secure Access Control System Information Disclosure Vulnerability
vendor_cisco·2017-02-15·CVSS 5.3
CVE-2017-3841 [MEDIUM] CWE-200 Cisco Secure Access Control System Information Disclosure Vulnerability
Cisco Secure Access Control System Information Disclosure Vulnerability
A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensitive information.
The vulnerability is due to the inclusion of sensitive information in a server response when certain pages of the web interface are accessed. An unauthenticated attacker with the ability to view configuration parameters could disclose passwords and other sensitive information about the affected system.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-acs3
Cisco
Cisco Secure Access Control System Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3841 Cisco Secure Access Control System Information Disclosure Vulnerability
CVE-2017-3841: Cisco Secure Access Control System Information Disclosure Vulnerability
A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensitive information. The vulnerability is due to the inclusion of sensitive information in a server response when certain pages of the web interface are accessed. An unauthenticated attacker with the ability to view configuration parameters could disclose passwords and other sensitive information about the affected system. There are no
CVSS: 3.0
CWE: CWE-200, CWE-200
Bug IDs: CSCvc04854
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/96237http://www.securitytracker.com/id/1037838https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-acs3http://www.securityfocus.com/bid/96237http://www.securitytracker.com/id/1037838https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-acs3
2017-02-22
Published