Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote attackers to cause a denial of service (crash) via a crafted RADIUS Access-Request packet. NOTE: it has been reported that at least one issue is a heap-based buffer overflow involving the Tunnel-Password attribute.
| Software | From | Fixed in |
|---|---|---|
| cisco / secure_access_control_server | 4.1 | 4.1.x |
| cisco / secure_access_control_server | - | 4.0.x |