Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2004-1099
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-1099

Description:
Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/17936

CISCO
  http://www.cisco.com/warp/public/707/cisco-sa-20041102-acs-eap-tls.shtml

CIAC
  http://www.ciac.org/ciac/bulletins/p-028.shtml

BID
  11577


Return to the previous page.