Secure Access Control System
Vendor:
First CVE: Apr 4, 2011 · Active for 15 years
35
Total CVEs
More Total CVEs than 96% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
2.9%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Secure Access Control System over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 4, 2011
15 years ago
Most Recent CVE
May 2, 2018
3,006 days ago
CVE Severity & Scoring
Secure Access Control System35 CVEs
83%
11%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (22.9%)
Unknown27 (77.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (22.9%)
High0 (0.0%)
Unknown27 (77.1%)
User Interaction
None5 (14.3%)
Unknown27 (77.1%)
Required3 (8.6%)
Privileges Required
Low2 (5.7%)
High0 (0.0%)
None6 (17.1%)
Unknown27 (77.1%)
Top CVEs
Signals from CVEs in this product scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0147CRITICAL A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arb | Mar 8, 2018 | 9.8 | 77 | YES | NO |
CVE-2011-0951MEDIUM The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user pass | Apr 4, 2011 | 5.0 | 32 | NO | YES |
CVE-2018-0253CRITICAL A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected | May 2, 2018 | 9.8 | 31 | NO | NO |
CVE-2014-0650HIGH The web interface in Cisco Secure Access Control System (ACS) 5.x before 5.4 Patch 3 allows remote attackers to execute arbitrary operating-system commands via a request to this in | Jan 16, 2014 | 10.0 | 31 | NO | NO |
CVE-2014-0648HIGH The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements, which allows remote attackers | Jan 16, 2014 | 10.0 | 31 | NO | NO |
CVE-2017-3841HIGH A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensitive information. More Informa | Feb 22, 2017 | 7.5 | 24 | NO | NO |
CVE-2014-0649HIGH The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remote authenticated users to obtain | Jan 16, 2014 | 9.0 | 23 | NO | NO |
CVE-2014-0667MEDIUM The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated users to read arbitrary files | Jan 16, 2014 | 6.3 | 22 | NO | NO |
CVE-2013-1200MEDIUM Session fixation vulnerability in Cisco Secure Access Control System (ACS) allows remote attackers to hijack web sessions via unspecified vectors, aka Bug ID CSCud95787. | May 16, 2013 | 6.8 | 21 | NO | NO |
CVE-2014-0678MEDIUM The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack sessions and gain privileges v | Jan 25, 2014 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (35 CVEs).
CISA KEV
1 CVE
2.9% of CVEs· 96th percentile
Metasploit
1 CVE
2.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (35 CVEs).
Media Mentions
Signals from CVEs in this product scope (35 CVEs).
Top CNAs Publishing CVEs For Secure Access Control System
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.8\(2.5\) | 4 | 6.0 | 1.8% | 0 | 0 |
| 5.8\(1.5\) | 1 | 5.4 | 0.9% | 0 | 0 |
| 5.8\(0.8\) | 2 | 7.6 | 3.9% | 0 | 0 |
| 5.8\(0.32\) | 1 | 5.3 | 2.3% | 0 | 0 |
| 5.8 | 1 | 9.8 | 7.0% | 0 | 0 |
| 5.5\(0.1\) | 1 | 4.3 | 1.6% | 0 | 0 |
| 5.4.0.46.5 | 2 | 9.5 | 4.3% | 0 | 0 |
| 5.4.0.46.4 | 2 | 9.5 | 4.3% | 0 | 0 |
| 5.4.0.46.3 | 2 | 9.5 | 4.3% | 0 | 0 |
| 5.4.0.46.2 | 2 | 9.5 | 4.3% | 0 | 0 |
| 5.4.0.46.1 | 3 | 9.7 | 4.0% | 0 | 0 |
| 5.3.0.40.9 | 3 | 9.7 | 4.0% | 0 | 0 |
| 5.3.0.40.8 | 3 | 9.7 | 4.0% | 0 | 0 |
| 5.3.0.40.7 | 3 | 9.7 | 4.0% | 0 | 0 |
| 5.3.0.40.6 | 3 | 9.7 | 4.0% | 0 | 0 |
| 5.3.0.40.5 | 4 | 8.3 | 3.5% | 0 | 0 |
| 5.3.0.40.4 | 3 | 9.7 | 4.0% | 0 | 0 |
| 5.3.0.40.3 | 3 | 9.7 | 4.0% | 0 | 0 |
| 5.3.0.40.2 | 3 | 9.7 | 4.0% | 0 | 0 |
| 5.3.0.40.1 | 3 | 9.7 | 4.0% | 0 | 0 |