CVE-2014-8027

Cisco Secure Access Control System - Privilege Escalation to Network Device Administrator via RBAC

Title source: llm
STIX 2.1

Description

The RBAC component in Cisco Secure Access Control System (ACS) allows remote authenticated users to obtain Network Device Administrator privileges for Create, Delete, Read, and Update operations via crafted HTTP requests, aka Bug ID CSCuq79034.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71944
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/100558
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031516
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/62159

Scores

EPSS 0.0163
EPSS Percentile 73.8%

Details

CWE
CWE-264
Status published
Products (1)
cisco/secure_access_control_system
Published Jan 09, 2015
Tracked Since Feb 18, 2026