Cisco Secure Access Control System (ACS) Unauthorized Password Change Security Bypass Vulnerability
BID:47093
Info
Cisco Secure Access Control System (ACS) Unauthorized Password Change Security Bypass Vulnerability
| Bugtraq ID: | 47093 |
| Class: | Access Validation Error |
| CVE: |
CVE-2011-0951 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 30 2011 12:00AM |
| Updated: | Mar 30 2011 12:00AM |
| Credit: | Cisco. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Secure Access Control System (ACS) Unauthorized Password Change Security Bypass Vulnerability
Cisco Secure Access Control System (ACS) is prone to a security-bypass vulnerability because it fails to adequately restrict access to the password-change feature.
This issue is being tracked by Cisco Bug ID CSCtl77440.
An attacker can exploit this issue to change a user's password, thereby aiding in further attacks.
Cisco Secure Access Control System (ACS) is prone to a security-bypass vulnerability because it fails to adequately restrict access to the password-change feature.
This issue is being tracked by Cisco Bug ID CSCtl77440.
An attacker can exploit this issue to change a user's password, thereby aiding in further attacks.
Exploit / POC
Cisco Secure Access Control System (ACS) Unauthorized Password Change Security Bypass Vulnerability
Attackers can exploit this issue with readily available tools.
Attackers can exploit this issue with readily available tools.
Solution / Fix
Cisco Secure Access Control System (ACS) Unauthorized Password Change Security Bypass Vulnerability
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.
References
Cisco Secure Access Control System (ACS) Unauthorized Password Change Security Bypass Vulnerability
References:
References:
- Cisco Homepage (Cisco )