CVE-2014-2130: Medium severity cisco secure access control server vulnerability
Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify application files and configuration files, and consequently execute arbitrary code, by leveraging administrative privileges, aka Bug ID CSCuj83189.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2130?
CVE-2014-2130 has a CVSS score indicating high severity due to its potential for remote code execution.
How do I fix CVE-2014-2130?
To mitigate CVE-2014-2130, update to the latest version of Cisco Secure Access Control System as per vendor guidance.
Who is affected by CVE-2014-2130?
CVE-2014-2130 affects users of Cisco Secure Access Control System that allow authenticated access to the web interface.
What can attackers do with CVE-2014-2130?
Attackers can exploit CVE-2014-2130 to modify application and configuration files, potentially leading to arbitrary code execution.
When was CVE-2014-2130 published?
CVE-2014-2130 was published in March 2014.