CVE-2013-5470: Input Validation
Cisco Secure Access Control System (ACS) does not properly handle requests to read from the TACACS+ socket, which allows remote attackers to cause a denial of service (process crash) via malformed TCP packets, aka Bug ID CSCuh12488.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5470?
CVE-2013-5470 is classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2013-5470?
To fix CVE-2013-5470, update your Cisco Secure Access Control System to the latest version that addresses this vulnerability.
What impact does CVE-2013-5470 have on my system?
CVE-2013-5470 can lead to a system crash by causing a denial of service through malformed TCP packets.
Who is affected by CVE-2013-5470?
CVE-2013-5470 affects users of Cisco Secure Access Control System who utilize TACACS+ for authentication.
Is CVE-2013-5470 being actively exploited?
There have been reports suggesting that CVE-2013-5470 may be actively exploited in the wild.