cbcvebase.

Cisco Secure Access Control Server vulnerabilities

33 known vulnerabilities affecting cisco/secure_access_control_server.

Total CVEs
33
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH12MEDIUM16

Vulnerabilities

Page 2 of 2
CVE-2002-0241P4HIGHCVSS 7.5v3.0.12002-05-29
CVE-2002-0241 [HIGH] CVE-2002-0241: NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.
nvd
CVE-2015-0746P4MEDIUMCVSS 5.0v5.5\(0.46.2\)2015-05-22
CVE-2015-0746 [MEDIUM] CWE-254 CVE-2015-0746: The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a den The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a denial of service (API outage) by sending many requests, aka Bug ID CSCut62022.
nvd
CVE-2002-0160P4MEDIUMCVSS 5.0v2.6v2.6.2+4 more2002-04-22
CVE-2002-0160 [MEDIUM] CVE-2002-0160: The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earli The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002.
nvd
CVE-2006-0561P4HIGHCVSS 7.2v3.0v3.0.1+5 more2006-05-10
CVE-2006-0561 [HIGH] CVE-2006-0561: Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the master key in the registry with insecure permissions, which allows local users and remote administrators to decrypt the passwords by using Microsoft's cryptographic API functions to obtain the plaintext version of the master key.
nvd
CVE-2004-1458P4MEDIUMCVSS 5.0v3.0v3.1+6 more2004-12-31
CVE-2004-1458 [MEDIUM] CVE-2004-1458: The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 1 The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 15 allows remote attackers to cause a denial of service (hang) via a flood of TCP connections to port 2002.
nvd
CVE-2015-6349P4MEDIUMCVSS 4.3v5.7.0.152015-10-30
CVE-2015-6349 [MEDIUM] CWE-79 CVE-2015-6349: Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-6346P4MEDIUMCVSS 4.3v5.7.0.152015-10-30
CVE-2015-6346 [MEDIUM] CWE-79 CVE-2015-6346: Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allow Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-6300P4MEDIUMCVSS 4.0v5.7.0.152015-09-20
CVE-2015-6300 [MEDIUM] CWE-20 CVE-2015-6300: Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) via crafted (1) CLI or (2) GUI commands, aka Bug ID CSCuw24694.
nvd
CVE-2015-6347P4MEDIUMCVSS 4.0v5.7.0.152015-10-30
CVE-2015-6347 [MEDIUM] CWE-264 CVE-2015-6347: The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticate The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and create a dashboard or portlet, by visiting an unspecified web page.
nvd
CVE-2015-6348P4MEDIUMCVSS 4.0v5.7.0.152015-10-30
CVE-2015-6348 [MEDIUM] CWE-264 CVE-2015-6348: The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (AC The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and read report or status information, by visiting an unspecified web page.
nvd
CVE-2011-3317P4MEDIUMCVSS 4.3v5.22012-05-02
CVE-2011-3317 [MEDIUM] CWE-79 CVE-2011-3317: Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Co Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtr78192.
nvd
CVE-2015-0729P4MEDIUMCVSS 4.3v5.5\(0.1\)2015-05-16
CVE-2015-0729 [MEDIUM] CWE-79 CVE-2015-0729: Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server Solution Engine (ACSE Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server Solution Engine (ACSE) 5.5(0.1) allows remote attackers to inject arbitrary web script or HTML via a file-inclusion attack, aka Bug ID CSCuu11005.
nvd
CVE-2002-1095P4MEDIUMCVSS 5.0v2.6.32002-10-04
CVE-2002-1095 [MEDIUM] CVE-2002-1095: Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cau Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set.
nvd
Cisco Secure Access Control Server vulnerabilities | cvebase