Cisco Secure Access Control Server CVE-2013-3466 Remote Command Execution Vulnerability
BID:62028
Info
Cisco Secure Access Control Server CVE-2013-3466 Remote Command Execution Vulnerability
| Bugtraq ID: | 62028 |
| Class: | Design Error |
| CVE: |
CVE-2013-3466 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 28 2013 12:00AM |
| Updated: | Aug 28 2013 12:00AM |
| Credit: | Brad Antoniewicz from McAfee and Foundstone Professional Services |
| Vulnerable: |
Cisco Secure ACS for Windows 4.2(0) Build 124 pat Cisco Secure ACS for Windows 4.1(4) Build 13 patc Cisco Secure ACS for Windows 4.1 |
| Not Vulnerable: | |
Discussion
Cisco Secure Access Control Server CVE-2013-3466 Remote Command Execution Vulnerability
Cisco Secure Access Control Server is prone to a remote command-execution vulnerability.
Remote attackers can exploit this issue to execute arbitrary commands. This may facilitate a complete compromise of an affected device.
This issue being tracked by Cisco Bug ID CSCui57636.
Cisco Secure Access Control Server 4.0 through versions 4.2.1.15 are vulnerable.
Cisco Secure Access Control Server is prone to a remote command-execution vulnerability.
Remote attackers can exploit this issue to execute arbitrary commands. This may facilitate a complete compromise of an affected device.
This issue being tracked by Cisco Bug ID CSCui57636.
Cisco Secure Access Control Server 4.0 through versions 4.2.1.15 are vulnerable.
Exploit / POC
Cisco Secure Access Control Server CVE-2013-3466 Remote Command Execution Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Cisco Secure Access Control Server CVE-2013-3466 Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Cisco Secure Access Control Server CVE-2013-3466 Remote Command Execution Vulnerability
References:
References: