Description
Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17118
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/11047
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20040825-acs.shtml
Scores
EPSS
0.0168
EPSS Percentile
74.5%
Details
Status
published
Products (9)
cisco/secure_access_control_server
3.0
cisco/secure_access_control_server
3.1
cisco/secure_access_control_server
3.2 (2 CPE variants)
cisco/secure_access_control_server
3.2\(1\)
cisco/secure_access_control_server
3.2\(2\)
cisco/secure_access_control_server
3.2\(3\)
cisco/secure_access_control_server
3.3
cisco/secure_access_control_server
3.3\(1\)
cisco/secure_acs_solution_engine
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026