Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-1099

Опубликовано: 10 янв. 2005
Источник: nvd
CVSS2: 10
EPSS Средний

Описание

Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:secure_access_control_server:3.3\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_access_control_server:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_acs_solution_engine:*:*:*:*:*:*:*:*

EPSS

Процентиль: 93%
0.1073
Средний

10 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username.

EPSS

Процентиль: 93%
0.1073
Средний

10 Critical

CVSS2

Дефекты

NVD-CWE-Other