First published: Wed Sep 04 2013(Updated: )
Cisco Secure Access Control System (ACS) does not properly handle requests to read from the TACACS+ socket, which allows remote attackers to cause a denial of service (process crash) via malformed TCP packets, aka Bug ID CSCuh12488.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Access Control System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5470 is classified as a high severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2013-5470, update your Cisco Secure Access Control System to the latest version that addresses this vulnerability.
CVE-2013-5470 can lead to a system crash by causing a denial of service through malformed TCP packets.
CVE-2013-5470 affects users of Cisco Secure Access Control System who utilize TACACS+ for authentication.
There have been reports suggesting that CVE-2013-5470 may be actively exploited in the wild.