Cisco Secure Access Control Server vulnerabilities
33 known vulnerabilities affecting cisco/secure_access_control_server.
Total CVEs
33
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH12MEDIUM16
Vulnerabilities
Page 2 of 2
CVE-2002-0241P4HIGHCVSS 7.5v3.0.12002-05-29
CVE-2002-0241 [HIGH] CVE-2002-0241: NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or
NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.
nvd
CVE-2015-0746P4MEDIUMCVSS 5.0v5.5\(0.46.2\)2015-05-22
CVE-2015-0746 [MEDIUM] CWE-254 CVE-2015-0746: The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a den
The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a denial of service (API outage) by sending many requests, aka Bug ID CSCut62022.
nvd
CVE-2002-0160P4MEDIUMCVSS 5.0v2.6v2.6.2+4 more2002-04-22
CVE-2002-0160 [MEDIUM] CVE-2002-0160: The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earli
The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002.
nvd
CVE-2006-0561P4HIGHCVSS 7.2v3.0v3.0.1+5 more2006-05-10
CVE-2006-0561 [HIGH] CVE-2006-0561: Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the
Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the master key in the registry with insecure permissions, which allows local users and remote administrators to decrypt the passwords by using Microsoft's cryptographic API functions to obtain the plaintext version of the master key.
nvd
CVE-2004-1458P4MEDIUMCVSS 5.0v3.0v3.1+6 more2004-12-31
CVE-2004-1458 [MEDIUM] CVE-2004-1458: The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 1
The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 15 allows remote attackers to cause a denial of service (hang) via a flood of TCP connections to port 2002.
nvd
CVE-2015-6349P4MEDIUMCVSS 4.3v5.7.0.152015-10-30
CVE-2015-6349 [MEDIUM] CWE-79 CVE-2015-6349: Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure
Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-6346P4MEDIUMCVSS 4.3v5.7.0.152015-10-30
CVE-2015-6346 [MEDIUM] CWE-79 CVE-2015-6346: Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allow
Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
nvd
CVE-2015-6300P4MEDIUMCVSS 4.0v5.7.0.152015-09-20
CVE-2015-6300 [MEDIUM] CWE-20 CVE-2015-6300: Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users
Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) via crafted (1) CLI or (2) GUI commands, aka Bug ID CSCuw24694.
nvd
CVE-2015-6347P4MEDIUMCVSS 4.0v5.7.0.152015-10-30
CVE-2015-6347 [MEDIUM] CWE-264 CVE-2015-6347: The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticate
The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and create a dashboard or portlet, by visiting an unspecified web page.
nvd
CVE-2015-6348P4MEDIUMCVSS 4.0v5.7.0.152015-10-30
CVE-2015-6348 [MEDIUM] CWE-264 CVE-2015-6348: The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (AC
The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and read report or status information, by visiting an unspecified web page.
nvd
CVE-2011-3317P4MEDIUMCVSS 4.3v5.22012-05-02
CVE-2011-3317 [MEDIUM] CWE-79 CVE-2011-3317: Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Co
Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtr78192.
nvd
CVE-2015-0729P4MEDIUMCVSS 4.3v5.5\(0.1\)2015-05-16
CVE-2015-0729 [MEDIUM] CWE-79 CVE-2015-0729: Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server Solution Engine (ACSE
Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server Solution Engine (ACSE) 5.5(0.1) allows remote attackers to inject arbitrary web script or HTML via a file-inclusion attack, aka Bug ID CSCuu11005.
nvd
CVE-2002-1095P4MEDIUMCVSS 5.0v2.6.32002-10-04
CVE-2002-1095 [MEDIUM] CVE-2002-1095: Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cau
Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set.
nvd
← Previous2 / 2