Show filters
37 Total Results
Displaying 11-20 of 37
Sort by:
Attacker Value
Unknown
CVE-2015-4219
Disclosure Date: June 24, 2015 (last updated October 05, 2023)
Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive information via brute-force attempts to send valid credentials, aka Bug IDs CSCue00833 and CSCub40331.
0
Attacker Value
Unknown
CVE-2015-0728
Disclosure Date: May 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Cisco Access Control Server (ACS) 5.5(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuu11002.
0
Attacker Value
Unknown
CVE-2014-2130
Disclosure Date: March 06, 2015 (last updated October 05, 2023)
Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify application files and configuration files, and consequently execute arbitrary code, by leveraging administrative privileges, aka Bug ID CSCuj83189.
0
Attacker Value
Unknown
CVE-2015-0580
Disclosure Date: February 12, 2015 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in the ACS View reporting interface pages in Cisco Secure Access Control System (ACS) before 5.5 patch 7 allow remote authenticated administrators to execute arbitrary SQL commands via crafted HTTPS requests, aka Bug ID CSCuq79027.
0
Attacker Value
Unknown
CVE-2014-8029
Disclosure Date: January 09, 2015 (last updated October 05, 2023)
Open redirect vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, aka Bug ID CSCuq74150.
0
Attacker Value
Unknown
CVE-2014-8027
Disclosure Date: January 09, 2015 (last updated October 05, 2023)
The RBAC component in Cisco Secure Access Control System (ACS) allows remote authenticated users to obtain Network Device Administrator privileges for Create, Delete, Read, and Update operations via crafted HTTP requests, aka Bug ID CSCuq79034.
0
Attacker Value
Unknown
CVE-2014-8028
Disclosure Date: January 09, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Secure Access Control System (ACS) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq79019.
0
Attacker Value
Unknown
CVE-2014-0678
Disclosure Date: January 25, 2014 (last updated October 05, 2023)
The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack sessions and gain privileges via unspecified vectors, aka Bug ID CSCue65951.
0
Attacker Value
Unknown
CVE-2014-0668
Disclosure Date: January 20, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the portal in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCue65949.
0
Attacker Value
Unknown
CVE-2014-0649
Disclosure Date: January 16, 2014 (last updated October 05, 2023)
The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remote authenticated users to obtain superadmin access via a request to this interface, aka Bug ID CSCud75180.
0