CVE-2007-1068
The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client store transmitted authentication credentials in plaintext log files, which allows local users to obtain sensitive information by reading these files, aka CSCsg34423.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- cisco/secure services client · cisco/security agent · cisco/trust agent · meetinghouse/aegis secureconnect client
- Source
- cve@mitre.org
References
- http://osvdb.org/33046
- http://secunia.com/advisories/24258Vendor Advisory
- http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/22648
- http://www.securitytracker.com/id?1017683
- http://www.securitytracker.com/id?1017684
- http://www.vupen.com/english/advisories/2007/0690Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32626
- http://osvdb.org/33046
- http://secunia.com/advisories/24258Vendor Advisory
- http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/22648
- http://www.securitytracker.com/id?1017683
- http://www.securitytracker.com/id?1017684
- http://www.vupen.com/english/advisories/2007/0690Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32626
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.