CVE-2011-0951: Medium severity cisco secure access control server vulnerability
The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user passwords via unspecified vectors, aka Bug ID CSCtl77440.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0951?
CVE-2011-0951 is classified as a high-severity vulnerability that allows attackers to change arbitrary user passwords.
How do I fix CVE-2011-0951?
To mitigate CVE-2011-0951, you should upgrade to Cisco Secure Access Control System version 5.2.0.26.3 or later, or 5.1.0.44.6 or later.
Which versions of Cisco Secure Access Control System are affected by CVE-2011-0951?
CVE-2011-0951 affects Cisco Secure Access Control System versions 5.1 and 5.2 prior to their respective patched releases.
What type of attack is facilitated by CVE-2011-0951?
CVE-2011-0951 facilitates remote attacks that can lead to unauthorized password changes for users.
Is there a workaround for CVE-2011-0951?
There is no documented workaround for CVE-2011-0951, so the recommended action is to apply the software update.