CVE-2004-1459: Medium severity Cisco Secure Access Control Server vulnerability
Cisco Secure Access Control Server (ACS) 3.2, when configured as a Light Extensible Authentication Protocol (LEAP) RADIUS proxy, allows remote attackers to cause a denial of service (device crash) via certain LEAP authentication requests.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1459?
CVE-2004-1459 is rated as a high severity vulnerability due to its potential to cause a denial of service attack.
How do I fix CVE-2004-1459?
To mitigate CVE-2004-1459, upgrade Cisco Secure Access Control Server to a version that includes the necessary patches.
What attacks can be performed using CVE-2004-1459?
CVE-2004-1459 allows remote attackers to send crafted LEAP authentication requests, leading to device crashes.
Which versions of Cisco software are affected by CVE-2004-1459?
CVE-2004-1459 impacts Cisco Secure Access Control Server versions 3.2, 3.0, 3.1, and 3.3.
Is Cisco Secure ACS Solution Engine affected by CVE-2004-1459?
Yes, Cisco Secure ACS Solution Engine is also vulnerable to CVE-2004-1459 when configured as a LEAP RADIUS proxy.