Authentication Bypass Vulnerability in Cisco Secure Access Control System
CVE-2012-5424
Currently unrated
Summary
An authentication bypass vulnerability exists in Cisco Secure Access Control System due to improper password validation when using specific configurations involving TACACS+ and LDAP. This flaw allows remote attackers to gain unauthorized access by providing a valid username along with a specially crafted password string. Organizations using affected versions of Cisco ACS are urged to apply the necessary patches to mitigate this security risk.
References
Timeline
Vulnerability published
Vulnerability Reserved