CVE-2006-4097

Cisco Secure Access Control Server < 4.1 - Denial of Service via Crafted RADIUS Access-Request Packet

Title source: llm
STIX 2.1

Description

Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote attackers to cause a denial of service (crash) via a crafted RADIUS Access-Request packet. NOTE: it has been reported that at least one issue is a heap-based buffer overflow involving the Tunnel-Password attribute.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/31334
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23629
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21900
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/443108
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0068
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017475
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/36125
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20070105-csacs.shtml

Scores

EPSS 0.0412
EPSS Percentile 89.7%

Details

Status published
Products (2)
cisco/secure_access_control_server 4.1
cisco/secure_access_control_server < 4.0
Published Dec 31, 2006
Tracked Since Feb 18, 2026