CVE-2004-1460

Cisco Secure Access Control Server <3.2(3) - Privilege Escalation

Title source: llm
STIX 2.1

Description

Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authenticating NDS users with NDS, allows remote attackers to gain unauthorized access to AAA clients via a blank password.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11047
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17117
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtml

Scores

EPSS 0.0157
EPSS Percentile 72.8%

Details

Status published
Products (9)
cisco/secure_access_control_server 3.0
cisco/secure_access_control_server 3.1
cisco/secure_access_control_server 3.2 (2 CPE variants)
cisco/secure_access_control_server 3.2\(1\)
cisco/secure_access_control_server 3.2\(2\)
cisco/secure_access_control_server 3.2\(3\)
cisco/secure_access_control_server 3.3
cisco/secure_access_control_server 3.3\(1\)
cisco/secure_acs_solution_engine
Published Dec 31, 2004
Tracked Since Feb 18, 2026