Vulnerabilities (CVE)

Filtered by vendor Cisco Subscribe
Filtered by product Secure Access Control Server Solution Engine
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-3380 1 Cisco 1 Secure Access Control Server Solution Engine 2018-10-30 4.0 MEDIUM N/A
The administrative web interface in the Access Control Server in Cisco Secure Access Control System (ACS) does not properly restrict the report view page, which allows remote authenticated users to obtain sensitive information via a direct request, aka Bug ID CSCue79279.
CVE-2015-0700 1 Cisco 1 Secure Access Control Server Solution Engine 2017-01-06 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in the Dashboard page in the monitoring-and-report section in Cisco Secure Access Control Server Solution Engine before 5.5(0.46.5) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj62924.