First published: Thu Jan 16 2014(Updated: )
The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated users to read arbitrary files via a request to this interface, aka Bug ID CSCud75169.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Access Control System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0667 has a high severity rating due to the potential for unauthorized file access by authenticated users.
To fix CVE-2014-0667, apply the security patches provided in the latest update from Cisco for the Secure Access Control System.
CVE-2014-0667 affects Cisco Secure Access Control System versions without the required security updates.
The impact of CVE-2014-0667 allows remote authenticated users to read arbitrary files, potentially leading to data exposure.
Yes, CVE-2014-0667 is a remote vulnerability that can be exploited by authenticated users to access sensitive files.