CVE-2002-0159
Summary
| CVE | CVE-2002-0159 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-04-22 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Secure Access Control Server | 2.6 | All | All | All |
| Application | Cisco | Secure Access Control Server | 2.6.2 | All | All | All |
| Application | Cisco | Secure Access Control Server | 2.6.3 | All | All | All |
| Application | Cisco | Secure Access Control Server | 2.6.4 | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.0 | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CiscoSecure ACS For Windows Format String Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| www.osvdb.org/2062 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Cisco - Cisco Security Advisory: Web Interface Vulnerabilities in Cisco Secure ACS for Windows | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| ISS X-Force Database: ciscosecure-acs-format-string (8742): Cisco Secure ACS format string | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.