7.5
CVE-2004-1461
- EPSS 1.68%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:07:45
- Erkennungen
Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Secure Access Control Server Version 3.0
Cisco ≫ Secure Access Control Server Version 3.1
Cisco ≫ Secure Access Control Server Version 3.2
Cisco ≫ Secure Access Control Server Version 3.2 Edition windows_server
Cisco ≫ Secure Access Control Server Version 3.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.68% | 0.739 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtml
http://www.securityfocus.com/bid/11047
https://exchange.xforce.ibmcloud.com/vulnerabilities/17118