Authentication and Authorization Bypass in Cisco Secure Access Control System
CVE-2014-0648
Currently unrated
What is CVE-2014-0648?
The RMI interface in Cisco Secure Access Control System (ACS) versions 5.x prior to 5.5 lacks proper enforcement of authentication and authorization protocols. This oversight allows remote attackers to gain unauthorized administrative access by sending a crafted request to the RMI interface, posing significant security risks to affected systems. Administrators are urged to apply available patches and follow best practices to mitigate exploitation risks.