CVE-2004-1099
high · 10Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username.
10
CVSS
10.2%
EPSS (exploit prob.)
95th
EPSS percentile
2005-01-10
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| cisco | secure_access_control_server | 3.3(1) |
| cisco | secure_access_control_server | 3.3.1 |
| cisco | secure_acs_solution_engine | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.ciac.org/ciac/bulletins/p-028.shtml
- http://www.cisco.com/warp/public/707/cisco-sa-20041102-acs-eap-tls.shtml
- http://www.securityfocus.com/bid/11577
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17936
- http://www.ciac.org/ciac/bulletins/p-028.shtml
- http://www.cisco.com/warp/public/707/cisco-sa-20041102-acs-eap-tls.shtml
- http://www.securityfocus.com/bid/11577
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17936
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2004-1099