ID

VAR-200012-0058


CVE

CVE-2000-1055


TITLE

CiscoSecure ACS Server Denial of service vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200012-013

DESCRIPTION

Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet. If a remote attacker is capable of sniffing or injecting traffic in between a server running CiscoSecure ACS for Windows NT and a TACACS+ client, CiscoSecure ACS for Windows NT can be made to crash if an oversized TACACS+ packet is sent to it. CiscoSecure ACS Server 2.4(2) and earlier versions have a buffer overflow vulnerability

Trust: 1.26

sources: NVD: CVE-2000-1055 // BID: 1706 // VULHUB: VHN-2625

AFFECTED PRODUCTS

vendor:ciscomodel:secure access control serverscope:eqversion:2.1

Trust: 1.6

vendor:ciscomodel:secure access control serverscope:eqversion:2.3\(3\)

Trust: 1.6

vendor:ciscomodel:secure access control serverscope:eqversion:2.4\(2\)

Trust: 1.6

vendor:ciscomodel:secure acs for windows ntscope:eqversion:2.42

Trust: 0.3

vendor:ciscomodel:secure access control serverscope:neversion: -

Trust: 0.3

sources: BID: 1706 // CNNVD: CNNVD-200012-013 // NVD: CVE-2000-1055

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2000-1055
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200012-013
value: CRITICAL

Trust: 0.6

VULHUB: VHN-2625
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2000-1055
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-2625
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-2625 // CNNVD: CNNVD-200012-013 // NVD: CVE-2000-1055

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2000-1055

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200012-013

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-200012-013

EXTERNAL IDS

db:BIDid:1706

Trust: 2.0

db:NVDid:CVE-2000-1055

Trust: 1.7

db:OSVDBid:1569

Trust: 1.7

db:CNNVDid:CNNVD-200012-013

Trust: 0.7

db:XFid:5273

Trust: 0.6

db:CISCOid:20000921 MULTIPLE VULNERABILITIES IN CISCOSECURE ACS FOR WINDOWS NT SERVER

Trust: 0.6

db:VULHUBid:VHN-2625

Trust: 0.1

sources: VULHUB: VHN-2625 // BID: 1706 // CNNVD: CNNVD-200012-013 // NVD: CVE-2000-1055

REFERENCES

url:http://www.securityfocus.com/bid/1706

Trust: 1.7

url:http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml

Trust: 1.7

url:http://www.osvdb.org/1569

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/5273

Trust: 1.1

url:http://xforce.iss.net/static/5273.php

Trust: 0.6

url:http://www.cisco.com/en/us/products/sw/voicesw/ps4625/index.html

Trust: 0.3

sources: VULHUB: VHN-2625 // BID: 1706 // CNNVD: CNNVD-200012-013 // NVD: CVE-2000-1055

CREDITS

Publicized in a Cisco Security Advisory (Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server) on September 21, 2000.

Trust: 0.3

sources: BID: 1706

SOURCES

db:VULHUBid:VHN-2625
db:BIDid:1706
db:CNNVDid:CNNVD-200012-013
db:NVDid:CVE-2000-1055

LAST UPDATE DATE

2024-08-14T14:16:23.155000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-2625date:2017-10-10T00:00:00
db:BIDid:1706date:2000-09-21T00:00:00
db:CNNVDid:CNNVD-200012-013date:2005-05-02T00:00:00
db:NVDid:CVE-2000-1055date:2017-10-10T01:29:27.843

SOURCES RELEASE DATE

db:VULHUBid:VHN-2625date:2000-12-11T00:00:00
db:BIDid:1706date:2000-09-21T00:00:00
db:CNNVDid:CNNVD-200012-013date:2000-12-11T00:00:00
db:NVDid:CVE-2000-1055date:2000-12-11T05:00:00