PT-2015-7164 · Cisco · Cisco Secure Access Control Server (Acs) Solution Engine
Published
2015-09-20
·
Updated
2016-12-29
·
CVE-2015-6300
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco Secure Access Control Server (ACS) Solution Engine version 5.7(0.15)
Description
The issue allows remote authenticated users to cause a denial of service, resulting in an SSH screen process crash. This can be achieved via crafted commands, either through the Command Line Interface (CLI) or the Graphical User Interface (GUI).
Recommendations
For Cisco Secure Access Control Server (ACS) Solution Engine version 5.7(0.15), consider restricting access to the SSH screen process until a fix is available. As a temporary workaround, limit the use of CLI and GUI commands to essential operations only. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Secure Access Control Server (Acs) Solution Engine