CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.
Info
Summary
CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml Patch
- http://www.securityfocus.com/bid/1708 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5274
- http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml Patch
- http://www.securityfocus.com/bid/1708 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5274
Timeline
- nvd_ingest NVD