First published: Wed May 29 2002(Updated: )
NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Access Control Server | =3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0241 is considered a medium severity vulnerability due to its potential impact on user authentication.
To fix CVE-2002-0241, update to a patched version of Cisco Secure Access Control Server that addresses this vulnerability.
CVE-2002-0241 affects Cisco Secure Access Control Server version 3.0.1 on Windows NT.
CVE-2002-0241 is an authentication vulnerability that allows expired or disabled users to gain access.
An attacker could gain unauthorized access to resources by exploiting CVE-2002-0241 if they have valid expired or disabled user credentials.