Back
CVE-2002-0159
Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002.
Published: Apr 22, 2002
Modified: Jun 16, 2026
CWE-134
CVSS Metrics
Affected Products (6)
| Vendor | Product | Version |
|---|---|---|
| cisco | secure_access_control_server | 2.6 |
| cisco | secure_access_control_server | 2.6.2 |
| cisco | secure_access_control_server | 2.6.3 |
| cisco | secure_access_control_server | 2.6.4 |
| cisco | secure_access_control_server | 3.0 |
| cisco | secure_access_control_server | 3.0.1 |
GitHub Security Advisory GHSA-gjqp-7xq4-7mr3
Format string vulnerability in the administration function in Cisco Secure Access Control Server ...
References (10)
- http://marc.info/?l=bugtraq&m=101787248913611&w=2
- http://www.cisco.com/warp/public/707/ACS-Win-Web.shtml Patch, Vendor Advisory
- http://www.iss.net/security_center/static/8742.php
- http://www.osvdb.org/2062
- http://www.securityfocus.com/bid/4416
- http://marc.info/?l=bugtraq&m=101787248913611&w=2
- http://www.cisco.com/warp/public/707/ACS-Win-Web.shtml Patch, Vendor Advisory
- http://www.iss.net/security_center/static/8742.php
- http://www.osvdb.org/2062
- http://www.securityfocus.com/bid/4416
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
5.44%
Top 8% most likely to be exploited
Threat Score
31.6 / 100
Data Sources
NVD
EPSS
GitHub