CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
89.8%
Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a “cryptographically correct” certificate with valid fields such as the username.
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | secure_access_control_server | 3.3(1) | cpe:2.3:a:cisco:secure_access_control_server:3.3\(1\):*:*:*:*:*:*:* |
cisco | secure_access_control_server | 3.3.1 | cpe:2.3:a:cisco:secure_access_control_server:3.3.1:*:*:*:*:*:*:* |
cisco | secure_acs_solution_engine | * | cpe:2.3:a:cisco:secure_acs_solution_engine:*:*:*:*:*:*:*:* |