CVE-2006-4098
Summary
| CVE | CVE-2006-4098 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-12-31 05:00:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted RADIUS Accounting-Request packet. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Secure Access Control Server | 3.0 | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.1 | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.2 | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.2.1 | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.2.2 | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.2\(1.20\) | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.2\(1\) | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.2\(2\) | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.2\(3\) | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.3 | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.3.1 | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.3.2 | All | All | All |
| Application | Cisco | Secure Access Control Server | 3.3\(1\) | All | All | All |
| Application | Cisco | Secure Access Control Server | 4.0 | All | All | All |
| Application | Cisco | Secure Access Control Server | 4.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| US-CERT Vulnerability Note VU#477164 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Cisco Secure Access Control Server Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - Cisco Secure Access Control Server CSAdmin and CSRadius Stack Overflows Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| osvdb.org/36126 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Cisco - Networking, Cloud, and Cybersecurity Solutions | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | |
| Cisco Secure ACS Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.