CVE-2013-3466

The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
ciscosecure_access_control_server
𝑥
≤ 4.2.1.15.10
ciscosecure_access_control_server
4.2.1.15.0
ciscosecure_access_control_server
4.2.1.15.1
ciscosecure_access_control_server
4.2.1.15.2
ciscosecure_access_control_server
4.2.1.15.3
ciscosecure_access_control_server
4.2.1.15.4
ciscosecure_access_control_server
4.2.1.15.6
ciscosecure_access_control_server
4.2.1.15.7
ciscosecure_access_control_server
4.2.1.15.8
ciscosecure_access_control_server
4.2.1.15.9
𝑥
= Vulnerable software versions