CVE-2002-0159

Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:secure_access_control_server:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_access_control_server:2.6.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_access_control_server:3.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_access_control_server:2.6:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_access_control_server:2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_access_control_server:2.6.3:*:*:*:*:*:*:*

Information

Published : 2002-04-21 21:00

Updated : 2016-10-17 19:16


NVD link : CVE-2002-0159

Mitre link : CVE-2002-0159


JSON object : View

CWE
CWE-134

Use of Externally-Controlled Format String

Advertisement

dedicated server usa

Products Affected

cisco

  • secure_access_control_server