Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-1460
CVE-2004-1460
Description
Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authenticating NDS users with NDS, allows remote attackers to gain unauthorized access to AAA clients via a blank password.
Affected products
10cpe:2.3:a:cisco:secure_access_control_server:3.0:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:cisco:secure_access_control_server:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_access_control_server:3.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_access_control_server:3.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_access_control_server:3.2\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_access_control_server:3.2\(2\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_access_control_server:3.2\(3\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_access_control_server:3.2:*:windows_server:*:*:*:*:*
- cpe:2.3:a:cisco:secure_access_control_server:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_access_control_server:3.3\(1\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:secure_acs_solution_engine:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.