Vulnerability Description
tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Tacacs\+ | f4.0.4alpha |
References
- http://online.securityfocus.com/archive/1/253288Vendor Advisory
- http://www.iss.net/security_center/static/8061.phpVendor Advisory
- http://www.securityfocus.com/bid/4003Vendor Advisory
- http://online.securityfocus.com/archive/1/253288Vendor Advisory
- http://www.iss.net/security_center/static/8061.phpVendor Advisory
- http://www.securityfocus.com/bid/4003Vendor Advisory
FAQ
What is CVE-2002-0225?
CVE-2002-0225 is a vulnerability with a CVSS score of 4.6 (MEDIUM). tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and m...
How severe is CVE-2002-0225?
CVE-2002-0225 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0225?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Tacacs\+.