← Vulnerability feed

Vulnerability record · CVE-2008-0532 · published 14 March 2008

CVE-2008-0532: Cisco Secure ACS UCP CSuserCGI.exe buffer overflow

Cisco · Acs For Windows

Multiple buffer overflows exist in securecgi-bin/CSuserCGI.exe in the User-Changeable Password (UCP) component of Cisco Secure ACS for Windows and ACS Solution Engine before 4.2. A remote attacker can trigger the overflow by supplying a long argument immediately after the Logout argument, and possibly through other unspecified vectors. The flaw allows arbitrary code execution on the affected system.

10.0 CVSS 2.0 High EPSS 57% · top 1.0% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
18References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument located immediately after the Logout argument, and possibly unspecified other vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, plus a high EPSS score and an exploit-tagged reference.

What it is

Multiple buffer overflows exist in securecgi-bin/CSuserCGI.exe in the User-Changeable Password (UCP) component of Cisco Secure ACS for Windows and ACS Solution Engine before 4.2. A remote attacker can trigger the overflow by supplying a long argument immediately after the Logout argument, and possibly through other unspecified vectors. The flaw allows arbitrary code execution on the affected system.

Impact

An unauthenticated remote attacker can execute arbitrary code with the privileges of the vulnerable CGI process, potentially leading to full compromise of the ACS host. Because ACS is an authentication and access-control server, compromise could also expose or subvert the credentials and policies it manages.

Attack surface

The vulnerability is reached over the network through the securecgi-bin/CSuserCGI.exe CGI endpoint, per the AV:N/AC:L/Au:N vector. No authentication or user interaction is required according to the CVSS vector and description.

Exploitation

The record is not listed in CISA KEV, but EPSS is high (0.57136, 99th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware association is documented.

What to do

  • Upgrade Cisco Secure ACS UCP to version 4.2 or later, or apply the vendor patch referenced in the Cisco security advisory.
  • If UCP is not required, disable or remove the User-Changeable Password component and the securecgi-bin/CSuserCGI.exe endpoint.
  • Restrict network access to the ACS web/CGI interface to trusted management networks only.
  • Monitor and audit the ACS host for unexpected process execution or file changes, since successful exploitation yields code execution.

Detection

  • Inspect web server and ACS logs for requests to securecgi-bin/CSuserCGI.exe containing unusually long arguments or the Logout parameter followed by oversized data.
  • Alert on HTTP requests to the UCP CGI path from untrusted or unexpected source addresses.
  • Monitor for child processes spawned by the ACS web/CGI service, which may indicate successful exploitation.
  • Review host-based logs for crashes or abnormal termination of CSuserCGI.exe.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-0532 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

4.3CVE-2008-0533Cisco acs for windows cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Acces…EPSS 29%3.5CVE-2007-1467Cisco acs solution engine vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Cl…EPSS 1.2%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed

Source: NIST National Vulnerability Database (record CVE-2008-0532), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.