ID

VAR-200704-0551


CVE

CVE-2007-1800


TITLE

Cisco Secure ACS Vulnerable to network access

Trust: 0.8

sources: JVNDB: JVNDB-2007-001772

DESCRIPTION

Cisco Secure ACS does not require authentication when Cisco Trust Agent (CTA) transmits posture information, which might allow remote attackers to gain network access via a spoofed Network Endpoint Assessment posture, aka "NACATTACK." NOTE: this attack might be limited to authenticated users and devices. Cisco Secure ACS is prone to a remote security vulnerability. Also known as \"NACATTACK\"

Trust: 1.98

sources: NVD: CVE-2007-1800 // JVNDB: JVNDB-2007-001772 // BID: 86387 // VULHUB: VHN-25162

AFFECTED PRODUCTS

vendor:ciscomodel:trust agentscope: - version: -

Trust: 1.4

vendor:ciscomodel:trust agentscope:eqversion:*

Trust: 1.0

vendor:ciscomodel:secure access control serverscope: - version: -

Trust: 0.3

sources: BID: 86387 // JVNDB: JVNDB-2007-001772 // CNNVD: CNNVD-200704-009 // NVD: CVE-2007-1800

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-1800
value: HIGH

Trust: 1.0

NVD: CVE-2007-1800
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200704-009
value: HIGH

Trust: 0.6

VULHUB: VHN-25162
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2007-1800
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-25162
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-25162 // JVNDB: JVNDB-2007-001772 // CNNVD: CNNVD-200704-009 // NVD: CVE-2007-1800

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2007-1800

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200704-009

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200704-009

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-001772

PATCH

title:Document ID: 614url:http://www.cisco.com/en/US/products/csr/cisco-sr-20070330-cta.html

Trust: 0.8

sources: JVNDB: JVNDB-2007-001772

EXTERNAL IDS

db:NVDid:CVE-2007-1800

Trust: 2.8

db:OSVDBid:34123

Trust: 1.7

db:JVNDBid:JVNDB-2007-001772

Trust: 0.8

db:CNNVDid:CNNVD-200704-009

Trust: 0.7

db:CISCOid:20070330 NACATTACK PRESENTATION

Trust: 0.6

db:BIDid:86387

Trust: 0.4

db:XFid:33557

Trust: 0.3

db:VULHUBid:VHN-25162

Trust: 0.1

sources: VULHUB: VHN-25162 // BID: 86387 // JVNDB: JVNDB-2007-001772 // CNNVD: CNNVD-200704-009 // NVD: CVE-2007-1800

REFERENCES

url:http://www.cisco.com/en/us/products/products_security_response09186a00808110da.html

Trust: 2.0

url:http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#dror

Trust: 2.0

url:http://osvdb.org/34123

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/33557

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-1800

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-1800

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/33557

Trust: 0.3

sources: VULHUB: VHN-25162 // BID: 86387 // JVNDB: JVNDB-2007-001772 // CNNVD: CNNVD-200704-009 // NVD: CVE-2007-1800

CREDITS

Unknown

Trust: 0.3

sources: BID: 86387

SOURCES

db:VULHUBid:VHN-25162
db:BIDid:86387
db:JVNDBid:JVNDB-2007-001772
db:CNNVDid:CNNVD-200704-009
db:NVDid:CVE-2007-1800

LAST UPDATE DATE

2025-04-10T23:16:46.752000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-25162date:2017-07-29T00:00:00
db:BIDid:86387date:2007-04-02T00:00:00
db:JVNDBid:JVNDB-2007-001772date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200704-009date:2007-04-03T00:00:00
db:NVDid:CVE-2007-1800date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-25162date:2007-04-02T00:00:00
db:BIDid:86387date:2007-04-02T00:00:00
db:JVNDBid:JVNDB-2007-001772date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200704-009date:2007-04-02T00:00:00
db:NVDid:CVE-2007-1800date:2007-04-02T23:19:00