9.3
CVSSv2

CVE-2013-3466

Published: 29/08/2013 Updated: 07/11/2016
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x prior to 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote malicious users to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco secure access control server

cisco secure access control server 4.2.1.15.9

cisco secure access control server 4.2.1.15.7

cisco secure access control server 4.2.1.15.4

cisco secure access control server 4.2.1.15.2

cisco secure access control server 4.2.1.15.1

cisco secure access control server 4.2.1.15.0

cisco secure access control server 4.2.1.15.8

cisco secure access control server 4.2.1.15.6

cisco secure access control server 4.2.1.15.3