CVE-2012-5424 Information
Feb 14, 2021
cve
Description
Cisco Secure Access Control System (ACS) 5.x before 5.2 Patch 11 and 5.3 before 5.3 Patch 7 when a certain configuration involving TACACS+ and LDAP is used does not properly validate passwords which allows remote attackers to bypass authentication by sending a valid username and a crafted password string aka Bug ID CSCuc65634.
Reference
http://osvdb.org/87251 http://secunia.com/advisories/51194 http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121107-acs http://www.securityfocus.com/bid/56433 http://www.securitytracker.com/id?1027733 https://exchange.xforce.ibmcloud.com/vulnerabilities/79860
Share on: