imPC@ndo IT

Tracker / CVE-2014-0650

CVE-2014-0650

High 10.0

The web interface in Cisco Secure Access Control System (ACS) 5.x before 5.4 Patch 3 allows remote attackers to execute arbitrary operating-system commands via a request to this interface, aka Bug ID CSCue65962.

Affected products and versions

cisco secure_access_control_system
cisco secure_access_control_system · … → 5.4.0.46.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References