Cisco-SA-20080903-CVE-2008-2441

Cisco Secure Access Control Server (ACS) Denial of Service Vulnerability

Medium · Updated · Cisco

1 product with CSAF evidence

Cisco Secure Access Control Server (ACS) contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability exists due to an error when handling Remote Authentication Dial In User Service (RADIUS) Extensible Authentication Protocol (EAP) responses. An authenticated, remote attacker could exploit this vulnerability by submitting a malicious RADIUS EAP response to the target system. This action could cause the authentication and authorization service and a service used to communicate with the device requesting authentication to crash, creating a DoS condition. Cisco has confirmed this vulnerability and released updated software. A successful attack could disrupt authentication services on the target system. By repeatedly sending malicious RADIUS EAP responses, the attacker could cause a persistent DoS condition. This situation could prevent devices that rely on authorization by an AAA server from connecting to the network.