Cross-site request forgery (CSRF) vulnerability in the Dashboard page in the monitoring-and-report section in Cisco Secure Access Control Server Solution Engine before 5.5(0.46.5) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj62924.
2015-04-17T01:59:27.030
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | cisco | secure_access_control_server_solution_engine | 5.4.0.46.6 | Yes |
| Application | cisco | secure_access_control_server_solution_engine | 5.5.0.36 | Yes |
| Application | cisco | secure_access_control_server_solution_engine | 5.5.0.46.4 | Yes |