Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify application files and configuration files, and consequently execute arbitrary code, by leveraging administrative privileges, aka Bug ID CSCuj83189.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2130 | Vendor Advisory |
http://www.securitytracker.com/id/1031844 |
Configurations
Information
Published : 2015-03-05 18:59
Updated : 2015-11-30 11:03
NVD link : CVE-2014-2130
Mitre link : CVE-2014-2130
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
cisco
- secure_access_control_system