CVE detail
CVE-2006-4098 — CVE-2006-4098
Published 2006-12-31 · Modified 2026-06-16 · Vendor cisco · Product secure_access_control_server · Source nvd
UNKNOWN
severity
CVSS-derived band
0.1281
EPSS probability
exploitation probability, 30d
96.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted RADIUS Accounting-Request packet.
Remediation
| Product | Vulnerable range | Fixed version | Advisory |
|---|
| n/a n/a | — | not specified | advisory ↗ |
References