CVE-2002-0160: Cisco Secure Access Control Server

Medium severity, CVSS 5.0. EPSS: 2.4% chance of exploitation in the next 30 days.

The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002.

Affected products

  • Cisco Secure Access Control Server: version 2.6 only; version 2.6.2 only; version 2.6.3 only; version 2.6.4 only; version 3.0 only; version 3.0.1 only

Published 2002-04-22. Last modified 2026-06-16.