Skip to main content

Vendor/product archive

cisco / secure_access_control_system CVEs

Beta · best-effort

35 CVEs tagged to cisco / secure_access_control_system5 Critical, 1 High, 29 Medium, 0 Low, 0 Unrated.

CVE-2018-0253

Published May 2, 2018

A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affecte…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-0147

Published Mar 8, 2018

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute ar…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
52.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-12354

Published Nov 30, 2017

A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to view sensitive information on an affected…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6769

Published Aug 7, 2017

A vulnerability in the web-based management interface of the Cisco Secure Access Control System (ACS) could allow an authenticated, remote attacker to conduct a stored cross-site…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3841

Published Feb 22, 2017

A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensitive information. More Inform…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3840

Published Feb 22, 2017

A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, ak…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3839

Published Feb 22, 2017

An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3838

Published Feb 22, 2017

A vulnerability in Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against the us…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0728

Published May 15, 2015

Cross-site scripting (XSS) vulnerability in Cisco Access Control Server (ACS) 5.5(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2130

Published Mar 6, 2015

Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify applicati…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0580

Published Feb 12, 2015

Multiple SQL injection vulnerabilities in the ACS View reporting interface pages in Cisco Secure Access Control System (ACS) before 5.5 patch 7 allow remote authenticated administ…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-8029

Published Jan 9, 2015

Open redirect vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8028

Published Jan 9, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Secure Access Control System (ACS) allow remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8027

Published Jan 9, 2015

The RBAC component in Cisco Secure Access Control System (ACS) allows remote authenticated users to obtain Network Device Administrator privileges for Create, Delete, Read, and Up…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0678

Published Jan 25, 2014

The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack sessions and gain privileges…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0668

Published Jan 20, 2014

Cross-site scripting (XSS) vulnerability in the portal in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecifie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0667

Published Jan 16, 2014

The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated users to read arbitrary files…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0650

Published Jan 16, 2014

The web interface in Cisco Secure Access Control System (ACS) 5.x before 5.4 Patch 3 allows remote attackers to execute arbitrary operating-system commands via a request to this i…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-0649

Published Jan 16, 2014

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remote authenticated users to obtai…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-0648

Published Jan 16, 2014

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements, which allows remote attackers…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-0663

Published Jan 10, 2014

Cross-site scripting (XSS) vulnerability in the web framework in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an uns…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6974

Published Jan 10, 2014

Cross-site scripting (XSS) vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an uns…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6695

Published Dec 2, 2013

The RBAC implementation in Cisco Secure Access Control System (ACS) does not properly verify privileges for support-bundle downloads, which allows remote authenticated users to ob…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5536

Published Oct 24, 2013

Cisco Secure Access Control System (ACS) does not properly implement an incoming-packet firewall rule, which allows remote attackers to cause a denial of service (process crash) v…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 35 CVEsPage 1 of 2