CVE-2006-4097
published 2006-12-31CVE-2006-4097: Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before…
PriorityP336high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
4.12%
89.6th percentile
Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote attackers to cause a denial of service (crash) via a crafted RADIUS Access-Request packet. NOTE: it has been reported that at least one issue is a heap-based buffer overflow involving the Tunnel-Password attribute.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_server | <= 4.0 | — |
| cisco | secure_access_control_server | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Access Control Server Access-Request Handling Denial of Service Vulnerability
vendor_cisco·2007-01-05·CVSS 7.8
CVE-2006-4097 [HIGH] CWE-399 Cisco Secure Access Control Server Access-Request Handling Denial of Service Vulnerability
Cisco Secure Access Control Server Access-Request Handling Denial of Service Vulnerability
Cisco Secure Access Control Server for Windows and Cisco Secure Access Control Server Solution Engine contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vulnerability exists due to insufficient handling of malformed RADIUS Access-Request messages. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted RADIUS Access-Request network packet to an affected system, crashing the CSRadius process. This renders the system unresponsive to further RADIUS Authentication, Authorization, and Accounting requests.
Cisco has confirmed this vulnerability in a security advisory and released updated software
Cisco
Multiple Vulnerabilities in Cisco Secure Access Control Server
vendor_cisco
CVE-2006-4097 Multiple Vulnerabilities in Cisco Secure Access Control Server
CVE-2006-4097: Multiple Vulnerabilities in Cisco Secure Access Control Server
Certain versions of Cisco Secure Access Control Server (ACS) for Windows and the Cisco Secure ACS Solution Engine (here after both referred to as purely Cisco Secure ACS) are affected by multiple vulnerabilities that cause specific Cisco Secure services to crash. Two of the vulnerabilities may permit arbitrary code execution after exploitation of the specified vulnerability. Affected Cisco Secure ACS services, and the impact of the vulnerabilities are as follows: Specially Crafted HTTP GET Request Vulnerability: Processing a specially crafted HTTP GET request may crash the CSAdmin service. This vulnerability is also susceptible to a stack overflow condition. Specially Crafted RADIUS Accounting-Request Vulnerabili
GHSA
GHSA-7j4m-73mf-j53v: Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4
ghsa_unreviewed·2022-05-01
CVE-2006-4097 [HIGH] GHSA-7j4m-73mf-j53v: Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4
Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote attackers to cause a denial of service (crash) via a crafted RADIUS Access-Request packet. NOTE: it has been reported that at least one issue is a heap-based buffer overflow involving the Tunnel-Password attribute.
No detection rules found.
No writeups or analysis indexed.
http://osvdb.org/36125http://secunia.com/advisories/23629http://securitytracker.com/id?1017475http://www.cisco.com/warp/public/707/cisco-sa-20070105-csacs.shtmlhttp://www.kb.cert.org/vuls/id/443108http://www.securityfocus.com/bid/21900http://www.vupen.com/english/advisories/2007/0068https://exchange.xforce.ibmcloud.com/vulnerabilities/31334http://osvdb.org/36125http://secunia.com/advisories/23629http://securitytracker.com/id?1017475http://www.cisco.com/warp/public/707/cisco-sa-20070105-csacs.shtmlhttp://www.kb.cert.org/vuls/id/443108http://www.securityfocus.com/bid/21900http://www.vupen.com/english/advisories/2007/0068https://exchange.xforce.ibmcloud.com/vulnerabilities/31334
2006-12-31
Published