7.5
CVSSv2

CVE-2002-0159

Published: 22/04/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and previous versions and 3.x up to and including 3.01 (build 40), allows remote malicious users to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco secure access control server 3.0.1

cisco secure access control server 2.6.4

cisco secure access control server 3.0

cisco secure access control server 2.6

cisco secure access control server 2.6.2

cisco secure access control server 2.6.3

Vendor Advisories

Cisco Secure Access Control Server (ACS) for Windows contains two vulnerabilities One vulnerability can lead to the execution of an arbitrary code on an ACS server, and the second can lead to an unauthorized disclosure of information A patch is available for both vulnerabilities Cisco Secure ACS for Unix is not vulnerable No other Cis ...