5
CVSSv2

CVE-2011-0951

Published: 04/04/2011 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 540
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 prior to 5.1.0.44.6 and 5.2 prior to 5.2.0.26.3 allows remote malicious users to change arbitrary user passwords via unspecified vectors, aka Bug ID CSCtl77440.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco secure access control system 5.1.0.44.1

cisco secure access control system 5.1.0.44.2

cisco secure access control system 5.2.0.26.2

cisco secure access control system 5.1.0.44.3

cisco secure access control system 5.1.0.44.4

cisco secure access control system 5.1

cisco secure access control system 5.1.0.44

cisco secure access control system 5.2.0.26

cisco secure access control system 5.2.0.26.1

cisco secure access control system 5.1.0.44.5

cisco secure access control system 5.2

Vendor Advisories

A vulnerability exists in some Cisco Secure Access Control System (ACS) versions that could allow a remote, unauthenticated attacker to change the password of any user account to any value without providing the account's previous password Successful exploitation requires the user account to be defined on the internal identity store This vulnerab ...
Cisco Secure Access Control System (ACS) contains a vulnerability that could allow an unauthenticated, remote attacker to modify user passwords The vulnerability is due to improper security restrictions on user password change functions in the web-based management interface of the Cisco Secure ACS application An unauthenticated, remote attacker ...