CVE-2013-3466: Critical severity Cisco Secure Access Control Server vulnerability
The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3466?
CVE-2013-3466 is rated as a high-severity vulnerability due to its potential to allow remote attackers to execute arbitrary commands.
How do I fix CVE-2013-3466?
To fix CVE-2013-3466, upgrade your Cisco Secure Access Control Server to version 4.2.1.15.11 or later.
What versions of Cisco Secure Access Control Server are affected by CVE-2013-3466?
CVE-2013-3466 affects Cisco Secure Access Control Server versions 4.x prior to 4.2.1.15.11.
What type of attack does CVE-2013-3466 enable?
CVE-2013-3466 enables remote attackers to execute arbitrary commands via crafted EAP-FAST packets.
Is there a workaround for CVE-2013-3466?
There is no official workaround for CVE-2013-3466 other than applying the recommended software upgrade.