Cisco Secure Access Control System Portal Interface Access Security Bypass Vulnerability
BID:65144
Info
Cisco Secure Access Control System Portal Interface Access Security Bypass Vulnerability
| Bugtraq ID: | 65144 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-0678 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2014 12:00AM |
| Updated: | Jan 24 2014 12:00AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Secure Access Control System Portal Interface Access Security Bypass Vulnerability
Cisco Secure Access Control System is prone to a access security-bypass vulnerability because it fails to properly validate sessions.
An authenticated remote attacker can leverage this issue to bypass security restrictions and perform unauthorized actions with the privileges of another user. This may aid in further attacks.
This issue is tracked by Cisco Bug ID CSCue65951.
Cisco Secure Access Control System is prone to a access security-bypass vulnerability because it fails to properly validate sessions.
An authenticated remote attacker can leverage this issue to bypass security restrictions and perform unauthorized actions with the privileges of another user. This may aid in further attacks.
This issue is tracked by Cisco Bug ID CSCue65951.
Exploit / POC
Cisco Secure Access Control System Portal Interface Access Security Bypass Vulnerability
An attacker can use web browser to exploit this issue.
An attacker can use web browser to exploit this issue.
Solution / Fix
Cisco Secure Access Control System Portal Interface Access Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Secure Access Control System Portal Interface Access Security Bypass Vulnerability
References:
References:
- Cisco Homepage (Cisco )