CVE-2013-3466
published 2013-08-29CVE-2013-3466: The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not…
PriorityP261critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.12%
91.4th percentile
The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_server | <= 4.2.1.15.10 | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
| cisco | secure_access_control_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted EAP-FAST packets targeting Cisco Secure ACS RADIUS service; monitor for malformed or unexpected user identity fields in EAP-FAST authentication exchanges ↗
- →Alert on unauthenticated remote command execution attempts against Cisco Secure ACS 4.0 through 4.2.1.15 when configured as a RADIUS server; the attack vector is EAP-FAST user identity parsing (CWE-78 OS command injection) ↗
- →Scope detection to environments where Cisco Secure ACS is configured as a RADIUS server — the vulnerability is NOT present in TACACS+-only configurations ↗
- ·Vulnerability is only exploitable when Cisco Secure ACS is configured as a RADIUS server; TACACS+-only deployments are not affected ↗
- ·Affected versions are Cisco Secure ACS 4.0 through 4.2.1.15; fixed in 4.2.1.15.11 and later ↗
- ·There are no workarounds available for this vulnerability; patching is the only mitigation ↗
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Access Control Server Remote Command Execution Vulnerability
vendor_cisco·2013-08-28·CVSS 10.0
CVE-2013-3466 [CRITICAL] CWE-78 Cisco Secure Access Control Server Remote Command Execution Vulnerability
Cisco Secure Access Control Server Remote Command Execution Vulnerability
A vulnerability in the EAP-FAST authentication module of Cisco Secure Access Control Server (ACS) versions 4.0 through 4.2.1.15 could allow an unauthenticated, remote attacker to execute arbitrary commands on the Cisco Secure ACS server. This vulnerability is only present when Cisco Secure ACS is configured as a RADIUS server.
The vulnerability is due to improper parsing of user identities used for EAP-FAST authentication. An attacker could exploit this vulnerability by sending crafted EAP-FAST packets to an affected device. An exploit could allow the attacker to execute arbitrary commands on the Cisco Secure ACS server and take full control of the affected server.
There are no workarounds for this vulnerability.
Cisco
Cisco Secure Access Control Server Remote Command Execution Vulnerability
vendor_cisco
CVE-2013-3466 Cisco Secure Access Control Server Remote Command Execution Vulnerability
CVE-2013-3466: Cisco Secure Access Control Server Remote Command Execution Vulnerability
A vulnerability in the EAP-FAST authentication module of Cisco Secure Access Control Server (ACS) versions 4.0 through 4.2.1.15 could allow an unauthenticated, remote attacker to execute arbitrary commands on the Cisco Secure ACS server. This vulnerability is only present when Cisco Secure ACS is configured as a RADIUS server. The vulnerability is due to improper parsing of user identities used for EAP-FAST authentication. An attacker could exploit this vulnerability by sending crafted EAP-FAST packets to an affected device. An exploit could allow the attacker to execute arbitrary commands on the Cisco Secure ACS server and take full control of the affected server. There are no
CWE: CWE-78, CWE-78
Bug
GHSA
GHSA-w8rq-f28j-855v: The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4
ghsa_unreviewed·2022-05-17
CVE-2013-3466 [HIGH] CWE-287 GHSA-w8rq-f28j-855v: The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4
The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/96668http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130828-acshttp://www.securitytracker.com/id/1028958http://osvdb.org/96668http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130828-acshttp://www.securitytracker.com/id/1028958
2013-08-29
Published