Cisco / Secure Access Control Server
34 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2015-6349 | Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attack… | MEDIUM | 4.3 | Oct 30, 2015 |
| CVE-2015-6348 | The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass in… | MEDIUM | 4.0 | Oct 30, 2015 |
| CVE-2015-6347 | The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and create a… | MEDIUM | 4.0 | Oct 30, 2015 |
| CVE-2015-6346 | Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML v… | MEDIUM | 4.3 | Oct 30, 2015 |
| CVE-2015-6345 | SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to execute arbitrary… | MEDIUM | 6.5 | Oct 30, 2015 |
| CVE-2015-6300 | Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) vi… | MEDIUM | 4.0 | Sep 20, 2015 |
| CVE-2015-0746 | The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a denial of service (API outage) by sending many requests, aka B… | MEDIUM | 5.0 | May 22, 2015 |
| CVE-2015-0729 | Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server Solution Engine (ACSE) 5.5(0.1) allows remote attackers to inject arbitrary web… | MEDIUM | 4.3 | May 16, 2015 |
| CVE-2013-3466 | The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not… | HIGH | 9.3 | Aug 29, 2013 |
| CVE-2012-5424 | Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7, when a certain configuration involving TACACS+ and LDAP is used, d… | MEDIUM | 5.0 | Nov 7, 2012 |
| CVE-2011-3317 | Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arb… | MEDIUM | 4.3 | May 2, 2012 |
| CVE-2011-3293 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to hij… | MEDIUM | 6.8 | May 2, 2012 |
| CVE-2008-2441 | Cisco Secure ACS 3.x before 3.3(4) Build 12 patch 7, 4.0.x, 4.1.x before 4.1(4) Build 13 Patch 11, and 4.2.x before 4.2(0) Build 124 Patch 4 does not properly… | HIGH | 7.5 | Sep 4, 2008 |
| CVE-2007-0105 | Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows… | HIGH | 7.5 | Jan 9, 2007 |
| CVE-2006-4098 | Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow… | HIGH | 10.0 | Jan 8, 2007 |
| CVE-2006-4097 | Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before… | HIGH | 7.8 | Jan 8, 2007 |
| CVE-2006-3226 | Cisco Secure Access Control Server (ACS) 4.x for Windows uses the client's IP address and the server's port number to grant access to an HTTP server port for a… | HIGH | 7.5 | Jun 26, 2006 |
| CVE-2006-3101 | Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via… | MEDIUM | 4.3 | Jun 21, 2006 |
| CVE-2006-0561 | Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the master key in the registry with insecure permissions, which… | HIGH | 7.2 | May 9, 2006 |
| CVE-2005-4499 | The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generate… | HIGH | 7.5 | Dec 22, 2005 |
| CVE-2005-0356 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denia… | MEDIUM | 5.0 | May 31, 2005 |
| CVE-2004-1461 | Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the… | HIGH | 7.5 | Feb 13, 2005 |
| CVE-2004-1460 | Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authenticating NDS u… | HIGH | 7.5 | Feb 13, 2005 |
| CVE-2004-1458 | The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 15 allows remote attackers to cause a denial of service (han… | MEDIUM | 5.0 | Feb 13, 2005 |
| CVE-2004-1099 | Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-T… | HIGH | 10.0 | Dec 1, 2004 |
Showing 1 to 25 of 34 CVEs