CVE-2006-4098
published 2006-12-31CVE-2006-4098: Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1…
PriorityP356critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
12.72%
95.8th percentile
Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted RADIUS Accounting-Request packet.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fm3h-2rr5-p2c2: Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4
ghsa_unreviewed·2022-05-01
CVE-2006-4098 [HIGH] GHSA-fm3h-2rr5-p2c2: Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4
Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted RADIUS Accounting-Request packet.
Cisco
Cisco Secure Access Control Server Accounting-Request Buffer Overflow Vulnerability
vendor_cisco·2007-01-05·CVSS 10.0
CVE-2006-4098 [CRITICAL] CWE-119 Cisco Secure Access Control Server Accounting-Request Buffer Overflow Vulnerability
Cisco Secure Access Control Server Accounting-Request Buffer Overflow Vulnerability
Cisco Secure Access Control Server for Windows and Cisco Secure Access Control Server Solution Engine contain a vulnerability that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code.
The vulnerability exists due to insufficient input validation in the CSRadius service. An authenticated, remote attacker could exploit this vulnerability by submitting a malicious RADIUS Accounting-Request designed to cause a buffer overflow. This could allow the attacker to crash this service or execute arbitrary code with SYSTEM privileges.
Cisco has released a security advisory and released updated software.
To exploit this vulnerability, a remote attacker
Cisco
Multiple Vulnerabilities in Cisco Secure Access Control Server
vendor_cisco
CVE-2006-4098 Multiple Vulnerabilities in Cisco Secure Access Control Server
CVE-2006-4098: Multiple Vulnerabilities in Cisco Secure Access Control Server
Certain versions of Cisco Secure Access Control Server (ACS) for Windows and the Cisco Secure ACS Solution Engine (here after both referred to as purely Cisco Secure ACS) are affected by multiple vulnerabilities that cause specific Cisco Secure services to crash. Two of the vulnerabilities may permit arbitrary code execution after exploitation of the specified vulnerability. Affected Cisco Secure ACS services, and the impact of the vulnerabilities are as follows: Specially Crafted HTTP GET Request Vulnerability: Processing a specially crafted HTTP GET request may crash the CSAdmin service. This vulnerability is also susceptible to a stack overflow condition. Specially Crafted RADIUS Accounting-Request Vulnerabili
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/36126http://secunia.com/advisories/23629http://securitytracker.com/id?1017475http://www.cisco.com/warp/public/707/cisco-sa-20070105-csacs.shtmlhttp://www.kb.cert.org/vuls/id/477164http://www.securityfocus.com/bid/21900http://www.vupen.com/english/advisories/2007/0068https://exchange.xforce.ibmcloud.com/vulnerabilities/31327http://osvdb.org/36126http://secunia.com/advisories/23629http://securitytracker.com/id?1017475http://www.cisco.com/warp/public/707/cisco-sa-20070105-csacs.shtmlhttp://www.kb.cert.org/vuls/id/477164http://www.securityfocus.com/bid/21900http://www.vupen.com/english/advisories/2007/0068https://exchange.xforce.ibmcloud.com/vulnerabilities/31327
2006-12-31
Published