CVE-2014-0649

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remote authenticated users to obtain superadmin access via a request to this interface, aka Bug ID CSCud75180.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
ciscosecure_access_control_system
𝑥
≤ 5.4.0.46.6
ciscosecure_access_control_system
5.1
ciscosecure_access_control_system
5.1.0.44
ciscosecure_access_control_system
5.1.0.44.1
ciscosecure_access_control_system
5.1.0.44.2
ciscosecure_access_control_system
5.1.0.44.3
ciscosecure_access_control_system
5.1.0.44.4
ciscosecure_access_control_system
5.1.0.44.5
ciscosecure_access_control_system
5.2
ciscosecure_access_control_system
5.2.0.26
ciscosecure_access_control_system
5.2.0.26.1
ciscosecure_access_control_system
5.2.0.26.2
ciscosecure_access_control_system
5.3.0.40.1
ciscosecure_access_control_system
5.3.0.40.2
ciscosecure_access_control_system
5.3.0.40.3
ciscosecure_access_control_system
5.3.0.40.4
ciscosecure_access_control_system
5.3.0.40.5
ciscosecure_access_control_system
5.3.0.40.6
ciscosecure_access_control_system
5.3.0.40.7
ciscosecure_access_control_system
5.3.0.40.8
ciscosecure_access_control_system
5.3.0.40.9
ciscosecure_access_control_system
5.4.0.46.1
ciscosecure_access_control_system
5.4.0.46.2
ciscosecure_access_control_system
5.4.0.46.3
ciscosecure_access_control_system
5.4.0.46.4
ciscosecure_access_control_system
5.4.0.46.5
𝑥
= Vulnerable software versions
Common Weakness Enumeration