CVE-2011-0951
Cisco Secure ACS Unauthorized Password Change
Severity Score
5.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user passwords via unspecified vectors, aka Bug ID CSCtl77440.
La interfaz de gestión basada en web en Cisco Secure Access Control System ( ACS ) v5.1 y v5.2 antes de v5.1.0.44.6 5.2.0.26.3, permite a atacantes remotos cambiar las contraseñas de usuario de forma arbitraria a través de vectores no especificados, también conocido como CSCtl77440 ID de error.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2011-02-10 CVE Reserved
- 2011-03-30 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-255: Credentials Management Errors
CAPEC
References (7)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/43924 | 2017-08-17 | |
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b74117.shtml | 2017-08-17 | |
http://www.vupen.com/english/advisories/2011/0821 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Secure Access Control System Search vendor "Cisco" for product "Secure Access Control System" | 5.1 Search vendor "Cisco" for product "Secure Access Control System" and version "5.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Access Control System Search vendor "Cisco" for product "Secure Access Control System" | 5.1.0.44 Search vendor "Cisco" for product "Secure Access Control System" and version "5.1.0.44" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Access Control System Search vendor "Cisco" for product "Secure Access Control System" | 5.1.0.44.1 Search vendor "Cisco" for product "Secure Access Control System" and version "5.1.0.44.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Access Control System Search vendor "Cisco" for product "Secure Access Control System" | 5.1.0.44.2 Search vendor "Cisco" for product "Secure Access Control System" and version "5.1.0.44.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Access Control System Search vendor "Cisco" for product "Secure Access Control System" | 5.1.0.44.3 Search vendor "Cisco" for product "Secure Access Control System" and version "5.1.0.44.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Access Control System Search vendor "Cisco" for product "Secure Access Control System" | 5.1.0.44.4 Search vendor "Cisco" for product "Secure Access Control System" and version "5.1.0.44.4" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Access Control System Search vendor "Cisco" for product "Secure Access Control System" | 5.1.0.44.5 Search vendor "Cisco" for product "Secure Access Control System" and version "5.1.0.44.5" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Access Control System Search vendor "Cisco" for product "Secure Access Control System" | 5.2 Search vendor "Cisco" for product "Secure Access Control System" and version "5.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Access Control System Search vendor "Cisco" for product "Secure Access Control System" | 5.2.0.26 Search vendor "Cisco" for product "Secure Access Control System" and version "5.2.0.26" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Access Control System Search vendor "Cisco" for product "Secure Access Control System" | 5.2.0.26.1 Search vendor "Cisco" for product "Secure Access Control System" and version "5.2.0.26.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Secure Access Control System Search vendor "Cisco" for product "Secure Access Control System" | 5.2.0.26.2 Search vendor "Cisco" for product "Secure Access Control System" and version "5.2.0.26.2" | - |
Affected
|