Cisco Secure Access Control Server vulnerabilities
33 known vulnerabilities affecting cisco/secure_access_control_server.
Total CVEs
33
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH12MEDIUM16
Vulnerabilities
Page 1 of 2
CVE-2005-0356P3MEDIUMCVSS 5.0PoCv2.0v2.1+26 more2005-05-31
CVE-2005-0356 [MEDIUM] CVE-2005-0356: Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timest
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
nvd
CVE-2000-1054P3CRITICALCVSS 10.0PoCv2.1v2.3\(3\)+1 more2000-12-11
CVE-2000-1054 [CRITICAL] CVE-2000-1054: Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attacke
Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large packet.
nvd
CVE-2013-3466P2CRITICALCVSS 9.3≤ 4.2.1.15.10v4.2.1.15.0+8 more2013-08-29
CVE-2013-3466 [CRITICAL] CWE-287 CVE-2013-3466: The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.1
The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.
nvd
CVE-2006-4098P3CRITICALCVSS 10.0v3.0v3.1+13 more2006-12-31
CVE-2006-4098 [CRITICAL] CVE-2006-4098: Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for
Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted RADIUS Accounting-Request packet.
nvd
CVE-2004-1099P3CRITICALCVSS 10.0v3.3\(1\)v3.3.12005-01-10
CVE-2004-1099 [CRITICAL] CVE-2004-1099: Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server
Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct"
nvd
CVE-2007-0105P3HIGHCVSS 7.5≤ 4.0.12007-01-09
CVE-2007-0105 [HIGH] CVE-2007-0105: Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for W
Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.
nvd
CVE-2006-3101P4MEDIUMCVSS 4.3PoCv2.32006-06-21
CVE-2006-3101 [MEDIUM] CVE-2006-3101: Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows r
Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters.
nvd
CVE-2002-0938P4HIGHCVSS 7.5PoCv3.0v3.0.12002-10-04
CVE-2002-0938 [HIGH] CVE-2002-0938: Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitra
Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the action argument in a link to setup.exe.
nvd
CVE-2006-3226P3HIGHCVSS 7.5v4.0v4.0.12006-06-26
CVE-2006-3226 [HIGH] CVE-2006-3226: Cisco Secure Access Control Server (ACS) 4.x for Windows uses the client's IP address and the server
Cisco Secure Access Control Server (ACS) 4.x for Windows uses the client's IP address and the server's port number to grant access to an HTTP server port for an administration session, which allows remote attackers to bypass authentication via various methods, aka "ACS Weak Session Management Vulnerability."
nvd
CVE-2015-6345P3MEDIUMCVSS 6.5v5.7.0.152015-10-30
CVE-2015-6345 [MEDIUM] CWE-89 CVE-2015-6345: SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0
SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuw24700.
nvd
CVE-2004-1461P3HIGHCVSS 7.5v3.0v3.1+6 more2004-12-31
CVE-2004-1461 [HIGH] CVE-2004-1461: Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP co
Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.
nvd
CVE-2006-4097P3HIGHCVSS 7.8≤ 4.0v4.12006-12-31
CVE-2006-4097 [HIGH] CVE-2006-4097: Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (
Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote attackers to cause a denial of service (crash) via a crafted RADIUS Access-Request packet. NOTE: it has been reported that at least one issue is a heap-based buffer overflow involving the
nvd
CVE-2005-4499P3HIGHCVSS 7.5v2.0v2.1+26 more2005-12-22
CVE-2005-4499 [HIGH] CVE-2005-4499: The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL o
The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the username from the cleartext portion of a RADIUS s
nvd
CVE-2000-1055P4CRITICALCVSS 10.0v2.1v2.3\(3\)+1 more2000-12-11
CVE-2000-1055 [CRITICAL] CVE-2000-1055: Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a deni
Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet.
nvd
CVE-2004-1460P4HIGHCVSS 7.5v3.0v3.1+6 more2004-12-31
CVE-2004-1460 [HIGH] CVE-2004-1460: Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind
Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authenticating NDS users with NDS, allows remote attackers to gain unauthorized access to AAA clients via a blank password.
nvd
CVE-2002-0159P4HIGHCVSS 7.5v2.6v2.6.2+4 more2002-04-22
CVE-2002-0159 [HIGH] CWE-134 CVE-2002-0159: Format string vulnerability in the administration function in Cisco Secure Access Control Server (AC
Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002.
nvd
CVE-2012-5424P4MEDIUMCVSS 5.0v5.0v5.1+2 more2012-11-07
CVE-2012-5424 [MEDIUM] CWE-20 CVE-2012-5424: Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a
Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP is used, does not properly validate passwords, which allows remote attackers to bypass authentication by sending a valid username and a crafted password string, aka Bug ID CSCuc65634.
nvd
CVE-2000-1056P4HIGHCVSS 7.5v2.1v2.3\(3\)+1 more2000-12-11
CVE-2000-1056 [HIGH] CVE-2000-1056: CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on t
CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.
nvd
CVE-2003-0210P4HIGHCVSS 7.5v2.1v2.3+10 more2003-05-12
CVE-2003-0210 [HIGH] CVE-2003-0210: Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows rem
Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.
nvd
CVE-2011-3293P4MEDIUMCVSS 6.8v5.22012-05-02
CVE-2011-3293 [MEDIUM] CWE-352 CVE-2011-3293: Multiple cross-site request forgery (CSRF) vulnerabilities in the Solution Engine in Cisco Secure Ac
Multiple cross-site request forgery (CSRF) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences, aka Bug ID CSCtr78143.
nvd
1 / 2Next →