Release date:
Updated on:
Affected Systems:
Cisco Secure Access Control Server <= 5.4.0.46.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65016
CVE (CAN) ID: CVE-2014-0668
Cisco Secure Access Control System is an Access policy Control platform.
The portal website of Cisco Secure Access Control System (ACS) 5.4.0.46.3 and earlier versions has the cross-site scripting vulnerability, which allows remote attackers to inject arbitrary Web scripts or HTML.
<* Source: Cisco
Link: http://secunia.com/advisories/56543/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.cisco.com/go/psirt
Http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0668
Http://tools.cisco.com/security/center/viewAlert.x? AlertId = 32489
Http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0668