Authentication Bypass Vulnerability in Cisco Secure Access Control System
CVE-2012-5424

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
7 November 2012

Summary

An authentication bypass vulnerability exists in Cisco Secure Access Control System due to improper password validation when using specific configurations involving TACACS+ and LDAP. This flaw allows remote attackers to gain unauthorized access by providing a valid username along with a specially crafted password string. Organizations using affected versions of Cisco ACS are urged to apply the necessary patches to mitigate this security risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.