|
Cisco Secure ACS EAP Packet Denial of Service
|
|
Secunia Advisory:
|
SA31731
|
|
|
Release Date:
|
2008-09-04
|
|
Popularity:
|
3,288 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
DoS
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Cisco Secure ACS Solution Engine 3.x Cisco Secure ACS Solution Engine 4.x
|
|
| Software: | Cisco Secure ACS 3.x Cisco Secure ACS 4.x
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: A vulnerability has been reported in Cisco Secure Access Control Server (ACS), which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an input validation error in Cisco Secure ACS, which can be exploited to crash the "CSRadius" and "CSAuth" processes by sending a specially crafted EAP packet containing an overly large "length" value.
Successful exploitation may require knowledge of the RADIUS shared secret.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|