VulnerabilityModified
CVE-2002-0160
The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\..
MEDIUM 5.0EPSS 2.38%
Does this matter?
Lower severity and a low EPSS score (2.38%). Track it; it rarely justifies an emergency change on its own.
Description
The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.38% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- cisco/secure access control server
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=101786689128667&w=2
- http://www.cisco.com/warp/public/707/ACS-Win-Web.shtmlPatch, Vendor Advisory
- http://www.osvdb.org/5352
- http://marc.info/?l=bugtraq&m=101786689128667&w=2
- http://www.cisco.com/warp/public/707/ACS-Win-Web.shtmlPatch, Vendor Advisory
- http://www.osvdb.org/5352
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.