CVE

Id
9889  
CVE No.
CVE-2004-1461  
Status
Candidate  
Description
Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.  
Phase
Assigned (20050213)  
Votes
None (candidate not yet proposed)  
Comments