Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2013-6695

The RBAC implementation in Cisco Secure Access Control System (ACS) does not properly verify privileges for support-bundle downloads, which allows remote authenticated users to obtain sensitive information via a download action, as demonstrated by obtaining read access to the user database, aka Bug ID CSCuj39274.

SeverityMEDIUM
CVSS4.0
CWECWE-264
KEV
Published
Modified

Related Products

Product Advisory Evidence
Cisco Secure Access Control System (ACS) Cisco-SA-20131202-CVE-2013-6695 Cisco OpenVuln