← All CVEs

CVE-2004-1099

high · 10

Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username.

10
CVSS
10.2%
EPSS (exploit prob.)
95th
EPSS percentile
2005-01-10
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
ciscosecure_access_control_server3.3(1)
ciscosecure_access_control_server3.3.1
ciscosecure_acs_solution_engineall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-1099