← Vulnerability feed

Vulnerability record · CVE-2008-2441 · published 4 September 2008

CVE-2008-2441: Cisco secure acs vulnerability

Cisco · Secure Acs

Cisco Secure ACS 3.x before 3.3(4) Build 12 patch 7, 4.0.x, 4.1.x before 4.1(4) Build 13 Patch 11, and 4.2.x before 4.2(0) Build 124 Patch 4 does not properly handle an EAP Response packet in which the value of the length field exceeds the actual packet length, which allows remote authenticated users to cause a denial of service (CSRadius and CSAuth service crash) or possibly execute arbitrary code via a crafted RADIUS (1) EAP-Response/Identity, (2) EAP-Response/MD5, or (3) EAP-Response/TLS Message Attribute packet.

7.5 CVSS 2.0 High EPSS 3.0% · top 13.4% CWE-399 · CWE-399
7.5CVSS 2.0 base score
3.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Cisco Secure ACS 3.x before 3.3(4) Build 12 patch 7, 4.0.x, 4.1.x before 4.1(4) Build 13 Patch 11, and 4.2.x before 4.2(0) Build 124 Patch 4 does not properly handle an EAP Response packet in which the value of the length field exceeds the actual packet length, which allows remote authenticated users to cause a denial of service (CSRadius and CSAuth service crash) or possibly execute arbitrary code via a crafted RADIUS (1) EAP-Response/Identity, (2) EAP-Response/MD5, or (3) EAP-Response/TLS Message Attribute packet.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-2441 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-4098Cisco secure access control server vulnerabilityStack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before…EPSS 13%10.0CVE-2004-1099Cisco secure access control server vulnerabilityCisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when…EPSS 10%10.0CVE-2000-1054Cisco secure access control server vulnerabilityBuffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly exec…EPSS 8.4%10.0CVE-2000-1055Cisco secure access control server vulnerabilityBuffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary comm…EPSS 4.0%9.3CVE-2013-3466Cisco secure access control server improper authentication vulnerabilityThe EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled,…EPSS 5.1%7.8CVE-2006-4097Cisco secure access control server vulnerabilityMultiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engi…EPSS 4.3%7.5CVE-2007-0105Cisco secure access control server vulnerabilityStack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before …EPSS 11%7.5CVE-2006-3226Cisco secure access control server vulnerabilityCisco Secure Access Control Server (ACS) 4.x for Windows uses the client's IP address and the server's port number to grant access to an HTTP server …EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2008-2441), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.