Vulnerability Name: | CVE-2014-8029 (CCN-100548) | ||||||||
Assigned: | 2014-10-08 | ||||||||
Published: | 2015-01-08 | ||||||||
Updated: | 2017-09-08 | ||||||||
Summary: | Open redirect vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, aka Bug ID CSCuq74150. CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Informational | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-8029 Source: SECUNIA Type: UNKNOWN 62159 Source: CCN Type: Cisco Security Notice Cisco Secure Access Control Server Open Redirect Vulnerability Source: CISCO Type: Vendor Advisory 20150108 Cisco Secure Access Control Server Open Redirect Vulnerability Source: BID Type: UNKNOWN 71948 Source: CCN Type: BID-71948 Cisco Secure Access Control Server CVE-2014-8029 Open Redirection Vulnerability Source: SECTRACK Type: UNKNOWN 1031514 Source: XF Type: UNKNOWN cisco-secureacs-cve20148029-open-redirect(100548) Source: XF Type: UNKNOWN cisco-secureacs-cve20148029-open-redirect(100548) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |