VulnerabilityModified
CVE-2014-0667
The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated users to read arbitrary files via a request to this interface, aka Bug ID CSCud75169.
MEDIUM 6.3EPSS 1.41%
Does this matter?
Lower severity and a low EPSS score (1.41%). Track it; it rarely justifies an emergency change on its own.
Description
The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated users to read arbitrary files via a request to this interface, aka Bug ID CSCud75169.
- CVSS 2.0
- 6.3 MEDIUMAV:N/AC:M/Au:S/C:C/I:N/A:N
- EPSS
- 1.41% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/secure access control system
- Source
- psirt@cisco.com
References
- http://osvdb.org/102168
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0667Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32468Vendor Advisory
- http://www.securityfocus.com/bid/64983Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029641Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90497
- http://osvdb.org/102168
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0667Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32468Vendor Advisory
- http://www.securityfocus.com/bid/64983Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029641Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90497
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.