PT-2013-4416 · Cisco · Cisco Secure Access Control Server

Published

2013-08-29

·

Updated

2016-11-07

·

CVE-2013-3466

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Secure Access Control Server (ACS) versions 4.x before 4.2.1.15.11
Description The issue concerns the EAP-FAST authentication module, which does not properly parse user identities when a RADIUS server configuration is enabled. This allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets.
Recommendations For versions prior to 4.2.1.15.11, update to version 4.2.1.15.11 or later to resolve the issue. As a temporary workaround, consider disabling the EAP-FAST authentication module until a patch is available. Restrict access to the RADIUS server configuration to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3466

Affected Products

Cisco Secure Access Control Server