CVE-2013-6695

Cisco Secure Access Control System - Authenticated Sensitive Information Exposure via Support-Bundle Download

Title source: llm
STIX 2.1

Description

The RBAC implementation in Cisco Secure Access Control System (ACS) does not properly verify privileges for support-bundle downloads, which allows remote authenticated users to obtain sensitive information via a download action, as demonstrated by obtaining read access to the user database, aka Bug ID CSCuj39274.

References (1)

Core 1
Core References

Scores

EPSS 0.0095
EPSS Percentile 57.5%

Details

CWE
CWE-264
Status published
Products (1)
cisco/secure_access_control_system
Published Dec 02, 2013
Tracked Since Feb 18, 2026