Vulnerability Details CVE-2006-4097
Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote attackers to cause a denial of service (crash) via a crafted RADIUS Access-Request packet. NOTE: it has been reported that at least one issue is a heap-based buffer overflow involving the Tunnel-Password attribute.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 81.5%
CVSS Severity
CVSS v2 Score 7.8
Products affected by CVE-2006-4097
-
cpe:2.3:a:cisco:secure_access_control_server:-
-
cpe:2.3:a:cisco:secure_access_control_server:2.1
-
cpe:2.3:a:cisco:secure_access_control_server:2.1(4)
-
cpe:2.3:a:cisco:secure_access_control_server:2.3
-
cpe:2.3:a:cisco:secure_access_control_server:2.3(1)
-
cpe:2.3:a:cisco:secure_access_control_server:2.3(2)
-
cpe:2.3:a:cisco:secure_access_control_server:2.4
-
cpe:2.3:a:cisco:secure_access_control_server:2.4(1)
-
cpe:2.3:a:cisco:secure_access_control_server:2.5
-
cpe:2.3:a:cisco:secure_access_control_server:2.6
-
cpe:2.3:a:cisco:secure_access_control_server:2.6.2
-
cpe:2.3:a:cisco:secure_access_control_server:2.6.3
-
cpe:2.3:a:cisco:secure_access_control_server:2.6.4
-
cpe:2.3:a:cisco:secure_access_control_server:3.0
-
cpe:2.3:a:cisco:secure_access_control_server:3.0.1
-
cpe:2.3:a:cisco:secure_access_control_server:3.0.2
-
cpe:2.3:a:cisco:secure_access_control_server:3.0.3
-
cpe:2.3:a:cisco:secure_access_control_server:3.0.4
-
cpe:2.3:a:cisco:secure_access_control_server:3.1
-
cpe:2.3:a:cisco:secure_access_control_server:3.1.1
-
cpe:2.3:a:cisco:secure_access_control_server:3.1.2
-
cpe:2.3:a:cisco:secure_access_control_server:3.2
-
cpe:2.3:a:cisco:secure_access_control_server:3.2(1)
-
cpe:2.3:a:cisco:secure_access_control_server:3.2(1.20)
-
cpe:2.3:a:cisco:secure_access_control_server:3.2(2)
-
cpe:2.3:a:cisco:secure_access_control_server:3.2(2)_build_15
-
cpe:2.3:a:cisco:secure_access_control_server:3.2(3)
-
cpe:2.3:a:cisco:secure_access_control_server:3.2.1
-
cpe:2.3:a:cisco:secure_access_control_server:3.2.2
-
cpe:2.3:a:cisco:secure_access_control_server:3.2.3
-
cpe:2.3:a:cisco:secure_access_control_server:3.3
-
cpe:2.3:a:cisco:secure_access_control_server:3.3(1)
-
cpe:2.3:a:cisco:secure_access_control_server:3.3.1
-
cpe:2.3:a:cisco:secure_access_control_server:3.3.2
-
cpe:2.3:a:cisco:secure_access_control_server:3.3.3
-
cpe:2.3:a:cisco:secure_access_control_server:3.3.4
-
cpe:2.3:a:cisco:secure_access_control_server:4.0
-
cpe:2.3:a:cisco:secure_access_control_server:4.1