CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.
Link | Tags |
---|---|
http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/5274 | vdb entry |
http://www.securityfocus.com/bid/1708 | vdb entry patch vendor advisory |