7.2
CVE-2007-1068
- EPSS 0.35%
- Veröffentlicht 22.02.2007 01:28:00
- Zuletzt bearbeitet 16.06.2026 22:36:51
- Erkennungen
The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client store transmitted authentication credentials in plaintext log files, which allows local users to obtain sensitive information by reading these files, aka CSCsg34423.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Secure Services Client Version 4.0
Cisco ≫ Secure Services Client Version 4.0.5
Cisco ≫ Secure Services Client Version 4.0.51
Cisco ≫ Security Agent Version 5.0
Cisco ≫ Security Agent Version 5.1
Cisco ≫ Trust Agent Version 1.0
Cisco ≫ Trust Agent Version 2.0
Cisco ≫ Trust Agent Version 2.0.1
Cisco ≫ Trust Agent Version 2.1
Meetinghouse ≫ Aegis Secureconnect Client Version windows_platform
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.268 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
http://secunia.com/advisories/24258
http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtml
http://www.securityfocus.com/bid/22648
http://www.securitytracker.com/id?1017683
http://www.securitytracker.com/id?1017684
http://www.vupen.com/english/advisories/2007/0690
http://osvdb.org/33046
https://exchange.xforce.ibmcloud.com/vulnerabilities/32626