CVE-2009-1135
Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, via vectors involving attempted access to a network resource behind the ISA Server, aka "Radius OTP Bypass Vulnerability."
- CVSS 2.0
- 9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 26.45% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- microsoft/isa server
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/35784
- http://www.securitytracker.com/id?1022547
- http://www.us-cert.gov/cas/techalerts/TA09-195A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2009/1889
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-031
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5649
- http://secunia.com/advisories/35784
- http://www.securitytracker.com/id?1022547
- http://www.us-cert.gov/cas/techalerts/TA09-195A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2009/1889
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-031
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5649
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.