Cisco Secure ACS EAP Parsing Flaw Leading to Service Disruption
CVE-2008-2441

Currently unrated

Key Information:

Vendor

Cisco

Vendor
CVE Published:
4 September 2008

What is CVE-2008-2441?

The vulnerability in Cisco Secure ACS allows remote authenticated users to exploit the improper handling of EAP Response packets. By sending a crafted packet where the length field exceeds the actual packet length, attackers can initiate a denial of service condition resulting in crashes of CSRadius and CSAuth services. This flaw also opens the door to potential execution of arbitrary code through specifically designed RADIUS messages, such as EAP-Response/Identity, EAP-Response/MD5, or EAP-Response/TLS Message Attributes.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.