CVE-2011-0951
Summary
| CVE | CVE-2011-0951 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-04-04 12:27:36 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user passwords via unspecified vectors, aka Bug ID CSCtl77440. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Secure Access Control System | 5.1 | All | All | All |
| Application | Cisco | Secure Access Control System | 5.1.0.44 | All | All | All |
| Application | Cisco | Secure Access Control System | 5.1.0.44.1 | All | All | All |
| Application | Cisco | Secure Access Control System | 5.1.0.44.2 | All | All | All |
| Application | Cisco | Secure Access Control System | 5.1.0.44.3 | All | All | All |
| Application | Cisco | Secure Access Control System | 5.1.0.44.4 | All | All | All |
| Application | Cisco | Secure Access Control System | 5.1.0.44.5 | All | All | All |
| Application | Cisco | Secure Access Control System | 5.2 | All | All | All |
| Application | Cisco | Secure Access Control System | 5.2.0.26 | All | All | All |
| Application | Cisco | Secure Access Control System | 5.2.0.26.1 | All | All | All |
| Application | Cisco | Secure Access Control System | 5.2.0.26.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Secure Access Control System Management Interface Bug Lets Remote Users Change Arbitrary User Passwords - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Cisco Secure Access Control System Password Change Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Cisco Secure Access Control System (ACS) Unauthorized Password Change Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Cisco Security Advisory: Cisco Secure Access Control System Unauthorized Password Change Vulnerability - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.