Vulnerability record · CVE-2008-0532 · published 14 March 2008
CVE-2008-0532: Cisco Secure ACS UCP CSuserCGI.exe buffer overflow
Cisco · Acs For Windows
Multiple buffer overflows exist in securecgi-bin/CSuserCGI.exe in the User-Changeable Password (UCP) component of Cisco Secure ACS for Windows and ACS Solution Engine before 4.2. A remote attacker can trigger the overflow by supplying a long argument immediately after the Logout argument, and possibly through other unspecified vectors. The flaw allows arbitrary code execution on the affected system.
Description
Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument located immediately after the Logout argument, and possibly unspecified other vectors.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, plus a high EPSS score and an exploit-tagged reference.
What it is
Multiple buffer overflows exist in securecgi-bin/CSuserCGI.exe in the User-Changeable Password (UCP) component of Cisco Secure ACS for Windows and ACS Solution Engine before 4.2. A remote attacker can trigger the overflow by supplying a long argument immediately after the Logout argument, and possibly through other unspecified vectors. The flaw allows arbitrary code execution on the affected system.
Impact
An unauthenticated remote attacker can execute arbitrary code with the privileges of the vulnerable CGI process, potentially leading to full compromise of the ACS host. Because ACS is an authentication and access-control server, compromise could also expose or subvert the credentials and policies it manages.
Attack surface
The vulnerability is reached over the network through the securecgi-bin/CSuserCGI.exe CGI endpoint, per the AV:N/AC:L/Au:N vector. No authentication or user interaction is required according to the CVSS vector and description.
Exploitation
The record is not listed in CISA KEV, but EPSS is high (0.57136, 99th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware association is documented.
What to do
- Upgrade Cisco Secure ACS UCP to version 4.2 or later, or apply the vendor patch referenced in the Cisco security advisory.
- If UCP is not required, disable or remove the User-Changeable Password component and the securecgi-bin/CSuserCGI.exe endpoint.
- Restrict network access to the ACS web/CGI interface to trusted management networks only.
- Monitor and audit the ACS host for unexpected process execution or file changes, since successful exploitation yields code execution.
Detection
- Inspect web server and ACS logs for requests to securecgi-bin/CSuserCGI.exe containing unusually long arguments or the Logout parameter followed by oversized data.
- Alert on HTTP requests to the UCP CGI path from untrusted or unexpected source addresses.
- Monitor for child processes spawned by the ACS web/CGI service, which may indicate successful exploitation.
- Review host-based logs for crashes or abnormal termination of CSuserCGI.exe.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-0532 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-0532), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.