CVE-2013-3466: Cisco Secure Access Control Server
High severity, CVSS 9.3. EPSS: 5.1% chance of exploitation in the next 30 days.
The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.
Affected products
- Cisco Secure Access Control Server: up to and including 4.2.1.15.10; version 4.2.1.15.0 only; version 4.2.1.15.1 only; version 4.2.1.15.2 only; version 4.2.1.15.3 only; version 4.2.1.15.4 only; …
Published 2013-08-29. Last modified 2026-06-16.