Secure Access Control System

Vendor:

First CVE: Apr 4, 2011 · Active for 15 years

35
Total CVEs
More Total CVEs than 96% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
2.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Secure Access Control System over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 4, 2011
15 years ago
Most Recent CVE
May 2, 2018
3,006 days ago

CVE Severity & Scoring

Secure Access Control System35 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (22.9%)
Unknown27 (77.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (22.9%)
High0 (0.0%)
Unknown27 (77.1%)
User Interaction
None5 (14.3%)
Unknown27 (77.1%)
Required3 (8.6%)
Privileges Required
Low2 (5.7%)
High0 (0.0%)
None6 (17.1%)
Unknown27 (77.1%)

Top CVEs

Signals from CVEs in this product scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arb
Mar 8, 20189.877YESNO
The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user pass
Apr 4, 20115.032NOYES
A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected
May 2, 20189.831NONO
The web interface in Cisco Secure Access Control System (ACS) 5.x before 5.4 Patch 3 allows remote attackers to execute arbitrary operating-system commands via a request to this in
Jan 16, 201410.031NONO
The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements, which allows remote attackers
Jan 16, 201410.031NONO
A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensitive information. More Informa
Feb 22, 20177.524NONO
The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remote authenticated users to obtain
Jan 16, 20149.023NONO
The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated users to read arbitrary files
Jan 16, 20146.322NONO
Session fixation vulnerability in Cisco Secure Access Control System (ACS) allows remote attackers to hijack web sessions via unspecified vectors, aka Bug ID CSCud95787.
May 16, 20136.821NONO
The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack sessions and gain privileges v
Jan 25, 20145.520NONO

Exploit Exposure

Signals from CVEs in this product scope (35 CVEs).

CISA KEV
1 CVE
2.9% of CVEs· 96th percentile
Metasploit
1 CVE
2.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (35 CVEs).

Media Mentions

Signals from CVEs in this product scope (35 CVEs).

Top CNAs Publishing CVEs For Secure Access Control System

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.8\(2.5\)46.01.8%00
5.8\(1.5\)15.40.9%00
5.8\(0.8\)27.63.9%00
5.8\(0.32\)15.32.3%00
5.819.87.0%00
5.5\(0.1\)14.31.6%00
5.4.0.46.529.54.3%00
5.4.0.46.429.54.3%00
5.4.0.46.329.54.3%00
5.4.0.46.229.54.3%00
5.4.0.46.139.74.0%00
5.3.0.40.939.74.0%00
5.3.0.40.839.74.0%00
5.3.0.40.739.74.0%00
5.3.0.40.639.74.0%00
5.3.0.40.548.33.5%00
5.3.0.40.439.74.0%00
5.3.0.40.339.74.0%00
5.3.0.40.239.74.0%00
5.3.0.40.139.74.0%00