CVE-2008-2441: High severity cisco secure vulnerability
Cisco Secure ACS 3.x before 3.3(4) Build 12 patch 7, 4.0.x, 4.1.x before 4.1(4) Build 13 Patch 11, and 4.2.x before 4.2(0) Build 124 Patch 4 does not properly handle an EAP Response packet in which the value of the length field exceeds the actual packet length, which allows remote authenticated users to cause a denial of service (CSRadius and CSAuth service crash) or possibly execute arbitrary code via a crafted RADIUS (1) EAP-Response/Identity, (2) EAP-Response/MD5, or (3) EAP-Response/TLS Message Attribute packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2441?
CVE-2008-2441 is classified as a high severity vulnerability due to its potential to allow remote authenticated users to exploit the system.
How do I fix CVE-2008-2441?
To fix CVE-2008-2441, upgrade to Cisco Secure ACS version 3.3(4) Build 12 patch 7 or a later version.
Which Cisco products are affected by CVE-2008-2441?
CVE-2008-2441 affects Cisco Secure ACS versions before 3.3(4) Build 12 patch 7, 4.0.x, 4.1.x before 4.1(4) Build 13 Patch 11, and 4.2.x before 4.2(0) Build 124 Patch 4.
What is the impact of CVE-2008-2441?
The impact of CVE-2008-2441 can lead to unauthorized access or control over the Cisco Secure ACS system by exploiting improper packet handling.
Can CVE-2008-2441 be exploited remotely?
Yes, CVE-2008-2441 can be exploited remotely by authenticated users to disrupt the normal operations of the affected systems.