Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2004-1461

Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.

SeverityHIGH
CVSS7.5
CWENVD-CWE-Other
KEV
Published
Modified

Related Products

Product Advisory Evidence
Cisco Secure Access Control Server Solution Engine (ACSE) cisco-sa-20040825-acs Cisco OpenVuln
Cisco Secure Access Control Server (ACS) for Windows cisco-sa-20040825-acs Cisco OpenVuln