9
CVSSv2

CVE-2014-0649

Published: 16/01/2014 Updated: 29/08/2017
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The RMI interface in Cisco Secure Access Control System (ACS) 5.x prior to 5.5 does not properly enforce authorization requirements, which allows remote authenticated users to obtain superadmin access via a request to this interface, aka Bug ID CSCud75180.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco secure access control system 5.4.0.46.3

cisco secure access control system 5.4.0.46.4

cisco secure access control system 5.4.0.46.5

cisco secure access control system 5.3.0.40.6

cisco secure access control system 5.3.0.40.2

cisco secure access control system 5.3.0.40.3

cisco secure access control system 5.1

cisco secure access control system 5.1.0.44

cisco secure access control system 5.2.0.26

cisco secure access control system 5.2.0.26.1

cisco secure access control system 5.3.0.40.7

cisco secure access control system 5.1.0.44.3

cisco secure access control system 5.1.0.44.4

cisco secure access control system 5.4.0.46.1

cisco secure access control system 5.4.0.46.2

cisco secure access control system 5.3.0.40.4

cisco secure access control system 5.3.0.40.5

cisco secure access control system 5.1.0.44.1

cisco secure access control system 5.1.0.44.2

cisco secure access control system 5.2.0.26.2

cisco secure access control system

cisco secure access control system 5.3.0.40.1

cisco secure access control system 5.3.0.40.8

cisco secure access control system 5.3.0.40.9

cisco secure access control system 5.1.0.44.5

cisco secure access control system 5.2

Vendor Advisories

Cisco Secure Access Control System (ACS) is affected by the following vulnerabilities: Cisco Secure ACS RMI Privilege Escalation Vulernability Cisco Secure ACS RMI Unauthenticated User Access Vulnerability Cisco Secure ACS Operating System Command Injection Vulnerability Cisco Secure ACS uses the Remote Method Invocation (RMI ...

Recent Articles

Java bug burns Borg
The Register • Richard Chirgwin • 20 Jan 2014

Cisco tells users to patch RMI vuln

Cisco has asked users of its Secure Access Control System 5.5 or lower to implement an urgent patch, as it has spotted several problems with its RMI implementation. There are three independent bugs: one privilege escalation vuln (CVE ID CVE-2014-0649, here), an unauthenticated user access vulnerability (CVE 2014-0648 here), and CVE 2014-0650 (here) which is an operating system command injection vulnerability. The first two, Cisco says, arise from “insufficient authentication and authorisation ...