CVE-2006-4097
highCVSS v3 Base Score
7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS Score
1.8%
Exploitation probability in 30 days
Top 17% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
None
Integrity
None
Availability
C
Published: December 31, 2006 (7074 days ago)
Last Modified: April 23, 2026
Vendor: Cisco
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote attackers to cause a denial of service (crash) via a crafted RADIUS Access-Request packet. NOTE: it has been reported that at least one issue is a heap-based buffer overflow involving the Tunnel-Password attribute.
CWE
NVD-CWE-noinfoAffected Products
cisco secure access control server