Lucene search

K
cveCiscoCVE-2013-3466
HistoryAug 29, 2013 - 12:07 p.m.

CVE-2013-3466

2013-08-2912:07:53
CWE-287
cisco
web.nvd.nist.gov
26
cve-2013-3466
cisco
secure access control server
acs
radius
eap-fast
authentication
remote attack
arbitrary commands
vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.004

Percentile

72.3%

The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.

Affected configurations

Nvd
Node
ciscosecure_access_control_serverRange4.2.1.15.10
OR
ciscosecure_access_control_serverMatch4.2.1.15.0
OR
ciscosecure_access_control_serverMatch4.2.1.15.1
OR
ciscosecure_access_control_serverMatch4.2.1.15.2
OR
ciscosecure_access_control_serverMatch4.2.1.15.3
OR
ciscosecure_access_control_serverMatch4.2.1.15.4
OR
ciscosecure_access_control_serverMatch4.2.1.15.6
OR
ciscosecure_access_control_serverMatch4.2.1.15.7
OR
ciscosecure_access_control_serverMatch4.2.1.15.8
OR
ciscosecure_access_control_serverMatch4.2.1.15.9
VendorProductVersionCPE
ciscosecure_access_control_server*cpe:2.3:a:cisco:secure_access_control_server:*:*:*:*:*:*:*:*
ciscosecure_access_control_server4.2.1.15.0cpe:2.3:a:cisco:secure_access_control_server:4.2.1.15.0:*:*:*:*:*:*:*
ciscosecure_access_control_server4.2.1.15.1cpe:2.3:a:cisco:secure_access_control_server:4.2.1.15.1:*:*:*:*:*:*:*
ciscosecure_access_control_server4.2.1.15.2cpe:2.3:a:cisco:secure_access_control_server:4.2.1.15.2:*:*:*:*:*:*:*
ciscosecure_access_control_server4.2.1.15.3cpe:2.3:a:cisco:secure_access_control_server:4.2.1.15.3:*:*:*:*:*:*:*
ciscosecure_access_control_server4.2.1.15.4cpe:2.3:a:cisco:secure_access_control_server:4.2.1.15.4:*:*:*:*:*:*:*
ciscosecure_access_control_server4.2.1.15.6cpe:2.3:a:cisco:secure_access_control_server:4.2.1.15.6:*:*:*:*:*:*:*
ciscosecure_access_control_server4.2.1.15.7cpe:2.3:a:cisco:secure_access_control_server:4.2.1.15.7:*:*:*:*:*:*:*
ciscosecure_access_control_server4.2.1.15.8cpe:2.3:a:cisco:secure_access_control_server:4.2.1.15.8:*:*:*:*:*:*:*
ciscosecure_access_control_server4.2.1.15.9cpe:2.3:a:cisco:secure_access_control_server:4.2.1.15.9:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.004

Percentile

72.3%