Skip to main content

Vendor/product archive

cisco / secure_access_control_server CVEs

Beta · best-effort

35 CVEs tagged to cisco / secure_access_control_server5 Critical, 13 High, 17 Medium, 0 Low, 0 Unrated.

CVE-2015-6349

Published Oct 30, 2015

Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6348

Published Oct 30, 2015

The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrict…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6347

Published Oct 30, 2015

The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and create a dashboard or portlet…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6346

Published Oct 30, 2015

Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6345

Published Oct 30, 2015

SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to execute arbitrary SQL commands via a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6300

Published Sep 20, 2015

Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) via crafted (1) CLI or…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0746

Published May 22, 2015

The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a denial of service (API outage) by sending many requests, aka Bug ID CSCut62022.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0729

Published May 16, 2015

Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server Solution Engine (ACSE) 5.5(0.1) allows remote attackers to inject arbitrary web script or HTML via a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3466

Published Aug 29, 2013

The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5424

Published Nov 7, 2012

Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP is used, does not properly val…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3317

Published May 2, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3293

Published May 2, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to hijack the authenticati…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0105

Published Jan 9, 2007

Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4097

Published Dec 31, 2006

Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote att…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4098

Published Dec 31, 2006

Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-3226

Published Jun 26, 2006

Cisco Secure Access Control Server (ACS) 4.x for Windows uses the client's IP address and the server's port number to grant access to an HTTP server port for an administration ses…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3101

Published Jun 21, 2006

Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) S…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0561

Published May 10, 2006

Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the master key in the registry with insecure permissions, which allows local users…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 35 CVEsPage 1 of 2