CVE-2002-0160: Medium severity Cisco Secure Access Control Server vulnerability
The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0160?
CVE-2002-0160 is classified as a moderate severity vulnerability due to potential unauthorized access to sensitive files.
How do I fix CVE-2002-0160?
To fix CVE-2002-0160, upgrade to a version of Cisco Secure Access Control Server that is later than 3.0.1.
What versions of Cisco Secure Access Control Server are affected by CVE-2002-0160?
The versions affected by CVE-2002-0160 include 2.6.x up to 2.6.4 and 3.x through 3.0.1.
What type of attack can exploit CVE-2002-0160?
CVE-2002-0160 can be exploited by remote attackers to access files outside the web root using directory traversal techniques.
Is there a workaround for CVE-2002-0160?
A recommended workaround for CVE-2002-0160 is to restrict network access to the vulnerable server until an upgrade can be performed.