The RMI interface in Cisco Secure Access Control System (ACS) 5.x prior to 5.5 does not properly enforce authorization requirements, which allows remote authenticated users to obtain superadmin access via a request to this interface, aka Bug ID CSCud75180.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cisco secure access control system 5.4.0.46.3 |
||
cisco secure access control system 5.4.0.46.4 |
||
cisco secure access control system 5.4.0.46.5 |
||
cisco secure access control system 5.3.0.40.6 |
||
cisco secure access control system 5.3.0.40.2 |
||
cisco secure access control system 5.3.0.40.3 |
||
cisco secure access control system 5.1 |
||
cisco secure access control system 5.1.0.44 |
||
cisco secure access control system 5.2.0.26 |
||
cisco secure access control system 5.2.0.26.1 |
||
cisco secure access control system 5.3.0.40.7 |
||
cisco secure access control system 5.1.0.44.3 |
||
cisco secure access control system 5.1.0.44.4 |
||
cisco secure access control system 5.4.0.46.1 |
||
cisco secure access control system 5.4.0.46.2 |
||
cisco secure access control system 5.3.0.40.4 |
||
cisco secure access control system 5.3.0.40.5 |
||
cisco secure access control system 5.1.0.44.1 |
||
cisco secure access control system 5.1.0.44.2 |
||
cisco secure access control system 5.2.0.26.2 |
||
cisco secure access control system |
||
cisco secure access control system 5.3.0.40.1 |
||
cisco secure access control system 5.3.0.40.8 |
||
cisco secure access control system 5.3.0.40.9 |
||
cisco secure access control system 5.1.0.44.5 |
||
cisco secure access control system 5.2 |
Cisco tells users to patch RMI vuln
Cisco has asked users of its Secure Access Control System 5.5 or lower to implement an urgent patch, as it has spotted several problems with its RMI implementation. There are three independent bugs: one privilege escalation vuln (CVE ID CVE-2014-0649, here), an unauthenticated user access vulnerability (CVE 2014-0648 here), and CVE 2014-0650 (here) which is an operating system command injection vulnerability. The first two, Cisco says, arise from “insufficient authentication and authorisation ...