SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#477164

Cisco Secure Access Control Server fails to properly handle a specially crafted RADIUS Accounting-Request packet

Overview

A vulnerability in the RADIUS server supplied with Cisco Secure ACS products could allow a remote attacker to execute arbitrary code on an affected system.

I. Description

Cisco Secure ACS is a Remote Access Dial-In User Service (RADIUS) and Terminal Access Controller Access Control System Plus (TACACS+) security server. The RADIUS protocol is handled by the CSRadius component of the Cisco Secure ACS product which is run as a service in Windows under the Local System account.

A stack-based buffer overflow exists in the way the CSRadius service handles certain RADIUS Accounting-Request packets. This vulnerability may allow a remote attacker with the ability to craft RADIUS packets to execute arbitrary code or cause the CSRadius service to crash.

Cisco states that versions of the Cisco Secure Access Control Server for Windows and Cisco Secure Access Control Server Solution Engine prior to 4.1 are affected by this issue. Cisco also states that the RADIUS secret key that is shared between the Network Access Server (NAS) and the Cisco Secure ACS server and/or appliance is required to exploit this vulnerability.

II. Impact

A remote attacker with prior access to the shared RADIUS secret key material may be able to execute arbitrary code on an affected system or cause the CSRadius service on that system to crash. The attacker-supplied code would be executed with the privileges of the CSRadius service, typically Local System.

III. Solution

Upgrade


Cisco has published Cisco Security Advisory cisco-sa-20070105-csacs in response to this issue. Users of affected software are encouraged to review this advisory and upgrade their software accordingly.

Workarounds

In addition to updated versions of the software, Cisco has published several workarounds for this issue. Users, particularly those who are unable to upgrade the software, are encouraged to review the workarounds described in Cisco Security Advisory cisco-sa-20070105-csacs.

Systems Affected

VendorStatusDate NotifiedDate Updated
Cisco Systems, Inc.Vulnerable15-Jan-2007

References


http://www.cisco.com/warp/public/707/cisco-sa-20070110-csacs.shtml
http://www.niscc.gov.uk/niscc/docs/br-20070108-00015.html?lang=en
http://www.niscc.gov.uk/niscc/docs/re-20070108-00020.pdf?lang=en
http://www.securityfocus.com/bid/21900

Credit

This issue was reported by the NISCC Vulnerability Management Team. NISCC, in turn, thanks the CESG Vulnerability Research Group for reporting these issues to them.

This document was written by Chad R Dougherty.

Other Information

Date Public:2007-01-05
Date First Published:2007-01-15
Date Last Updated:2007-01-26
CERT Advisory: 
CVE-ID(s):CVE-2006-4098
NVD-ID(s):CVE-2006-4098
US-CERT Technical Alerts: 
Metric:8.98
Document Revision:10

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader