VulnerabilityModified
CVE-2001-0748
Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI.
MEDIUM 5.0EPSS 9.21%
Does this matter?
Lower severity and a low EPSS score (9.21%). Track it; it rarely justifies an emergency change on its own.
Description
Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 9.21% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- acme labs/acme server
- Source
- cve@mitre.org
References
- http://www.cisco.com/warp/public/707/acmeweb-acsunix-dirtravers-vuln-pub.shtmlThird Party Advisory
- http://www.iss.net/security_center/static/6634.phpBroken Link
- http://www.osvdb.org/5544Broken Link
- http://www.securityfocus.com/archive/1/188141Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/2809Third Party Advisory, VDB Entry
- http://www.cisco.com/warp/public/707/acmeweb-acsunix-dirtravers-vuln-pub.shtmlThird Party Advisory
- http://www.iss.net/security_center/static/6634.phpBroken Link
- http://www.osvdb.org/5544Broken Link
- http://www.securityfocus.com/archive/1/188141Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/2809Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.