SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-4566

The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to…

MEDIUM 6.4EPSS 1.50%

Does this matter?

Lower severity and a low EPSS score (1.50%). Track it; it rarely justifies an emergency change on its own.

Description

The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients, a different vulnerability than CVE-2012-4523.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS
1.50% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
uninett/radsecproxy
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.