Cisco Secure Access Control System (ACS) CVE-2013-1200 Session Fixation Vulnerability
BID:59943
Info
Cisco Secure Access Control System (ACS) CVE-2013-1200 Session Fixation Vulnerability
| Bugtraq ID: | 59943 |
| Class: | Unknown |
| CVE: |
CVE-2013-1200 |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2013 12:00AM |
| Updated: | May 21 2013 05:53AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Secure Access Control System (ACS) CVE-2013-1200 Session Fixation Vulnerability
Cisco Secure Access Control System (ACS) is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected device.
This issue is being tracked by Cisco Bug ID CSCud95787.
Cisco Secure Access Control System (ACS) is prone to a session-fixation vulnerability.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected device.
This issue is being tracked by Cisco Bug ID CSCud95787.
Exploit / POC
Cisco Secure Access Control System (ACS) CVE-2013-1200 Session Fixation Vulnerability
To exploit this issue an attacker entices an unsuspecting user into following a malicious URI.
To exploit this issue an attacker entices an unsuspecting user into following a malicious URI.
Solution / Fix
Cisco Secure Access Control System (ACS) CVE-2013-1200 Session Fixation Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Secure Access Control System (ACS) CVE-2013-1200 Session Fixation Vulnerability
References:
References: