First published: Mon Dec 11 2000(Updated: )
CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Access Control Server | =2.1 | |
Cisco Secure Access Control Server | =2.3\(3\) | |
Cisco Secure Access Control Server | =2.4\(2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1056 is classified as a high severity vulnerability due to its potential to allow unauthorized access.
To fix CVE-2000-1056, ensure that your LDAP server does not allow null passwords and update to a patched version of Cisco Secure ACS.
CVE-2000-1056 affects Cisco Secure ACS Server versions up to and including 2.4(2) and 2.3(3).
It is highly recommended to not use vulnerable versions of Cisco Secure ACS without applying necessary updates to mitigate CVE-2000-1056.
CVE-2000-1056 specifically affects LDAP authentication on the Cisco Secure ACS Server.