CVE-2014-0650

The web interface in Cisco Secure Access Control System (ACS) 5.x before 5.4 Patch 3 allows remote attackers to execute arbitrary operating-system commands via a request to this interface, aka Bug ID CSCue65962.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
ciscosecure_access_control_system
𝑥
≤ 5.4.0.46.2
ciscosecure_access_control_system
5.1
ciscosecure_access_control_system
5.1.0.44
ciscosecure_access_control_system
5.1.0.44.1
ciscosecure_access_control_system
5.1.0.44.2
ciscosecure_access_control_system
5.1.0.44.3
ciscosecure_access_control_system
5.1.0.44.4
ciscosecure_access_control_system
5.1.0.44.5
ciscosecure_access_control_system
5.2
ciscosecure_access_control_system
5.2.0.26
ciscosecure_access_control_system
5.2.0.26.1
ciscosecure_access_control_system
5.2.0.26.2
ciscosecure_access_control_system
5.3.0.40.1
ciscosecure_access_control_system
5.3.0.40.2
ciscosecure_access_control_system
5.3.0.40.3
ciscosecure_access_control_system
5.3.0.40.4
ciscosecure_access_control_system
5.3.0.40.5
ciscosecure_access_control_system
5.3.0.40.6
ciscosecure_access_control_system
5.3.0.40.7
ciscosecure_access_control_system
5.3.0.40.8
ciscosecure_access_control_system
5.3.0.40.9
ciscosecure_access_control_system
5.4.0.46.1
𝑥
= Vulnerable software versions