LiveActive security incident?Get immediate response
CVE Record

CVE-1999-0734: A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server...

A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

A legacy Cisco authentication server shipped with a default configuration that let anyone on the network change its database without logging in. In practical terms, an unauthenticated attacker with network access to the admin service could alter user records and access rules that governed who could log into network devices. This is a very old (1999) issue tied to a specific out-of-support product.

Executive priority

Low priority for modern environments. Treat as a legacy-system hygiene check rather than an active threat. The affected product is decades out of support, so the meaningful executive action is confirming that no forgotten CiscoSecure ACS UNIX servers still exist in the estate and that AAA services run on a currently supported platform.

Technical view

CVE-1999-0734 covers a default-configuration weakness in CiscoSecure Access Control Server (ACS) for UNIX where the remote administration interface permitted database modifications without authentication. Cisco advisory cisco-sa-19990819-dbaccess describes the exposure. No CVSS, CWE, or CPE data is published in the bundle. It is not listed in CISA KEV, and the affected product line is long end-of-life.

Likely exposure

Exposure today should be effectively zero: CiscoSecure ACS for UNIX was retired long ago and superseded by ACS for Windows and later Cisco ISE. Any remaining exposure would be limited to unmaintained legacy environments still running the affected 1999-era ACS UNIX build with the vulnerable default administration configuration reachable on the network.

Exploitation context

No evidence of active exploitation is cited. The CVE is not in CISA KEV, and no public exploit is referenced in the bundle. Cisco's 1999 advisory and the X-Force VDB entry document the weakness but do not report in-the-wild attacks. Given the product's age, the practical exploitation surface today is negligible outside museum systems.

Researcher notes

Source bundle lacks CVSS, CWE, and CPE detail; affected vendor/product is listed as n/a in CVE record even though the description clearly names CiscoSecure ACS for UNIX. Primary authoritative reference is the Cisco PSIRT advisory cisco-sa-19990819-dbaccess; X-Force VDB entry 3133 corroborates. No KEV listing and no cited exploit code. Treat any surviving instance as unsupported and out-of-scope for patching.

Mitigation direction

  • Confirm no CiscoSecure ACS for UNIX instances remain in the environment via asset inventory.
  • If any legacy ACS UNIX host is found, isolate it from production networks immediately.
  • Migrate authentication services to a supported platform such as Cisco ISE.
  • Apply Cisco's guidance in advisory cisco-sa-19990819-dbaccess if a legacy host must remain temporarily.
  • Restrict administrative interfaces to a dedicated management network with ACLs.
  • Decommission end-of-life AAA infrastructure as a standing hygiene task.

Validation and detection

  • Search CMDB and network scans for hosts identifying as CiscoSecure ACS for UNIX.
  • Review AAA/TACACS+ and RADIUS server inventories for legacy Cisco ACS entries.
  • Verify no administrative endpoints on suspected hosts respond without authentication.
  • Cross-check firewall and NAC logs for traffic to legacy ACS management ports.
  • Confirm authentication for network devices is served only by supported ISE or equivalent platforms.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Database behavior lookup

The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-1999-0734 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.