Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8rq-f28j-855v

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.

The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.

EPSS

Процентиль: 72%
0.00722
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 12 лет назад

The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.

EPSS

Процентиль: 72%
0.00722
Низкий

Дефекты

CWE-287