Cisco Secure ACS EAP Parsing Flaw Leading to Service Disruption
CVE-2008-2441
Currently unrated
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 4 September 2008
What is CVE-2008-2441?
The vulnerability in Cisco Secure ACS allows remote authenticated users to exploit the improper handling of EAP Response packets. By sending a crafted packet where the length field exceeds the actual packet length, attackers can initiate a denial of service condition resulting in crashes of CSRadius and CSAuth services. This flaw also opens the door to potential execution of arbitrary code through specifically designed RADIUS messages, such as EAP-Response/Identity, EAP-Response/MD5, or EAP-Response/TLS Message Attributes.