CVE-2002-0241

Cisco Secure ACS 3.0.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.

References (3)

Core 3
Core References
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8106.php
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4048
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/ciscosecure-acs-nds-authentication-vuln-pub.shtml

Scores

EPSS 0.0162
EPSS Percentile 73.6%

Details

Status published
Products (1)
cisco/secure_access_control_server 3.0.1
Published May 29, 2002
Tracked Since Feb 18, 2026