CVE-2014-2130

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
06/03/2015
Last modified:
12/04/2025

Description

Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify application files and configuration files, and consequently execute arbitrary code, by leveraging administrative privileges, aka Bug ID CSCuj83189.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:secure_access_control_system:-:*:*:*:*:*:*:*