Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2004-1099

EPSS 2.16% · P84
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2004-1099

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco ACS 绕过身份认证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Secure Access Control Server(ACS)是美国思科(Cisco)公司的一款安全访问控制服务器。该服务器为思科智能信息网络提供基于身份的全面的访问控制解决方案。 ACS Windows和ACS Solution Engine 3.3.1在启用EAP-TLS协议时,不能正确处理已过期或不可信证书。 远程攻击者可以借助一个包含用户名等有效字段的"cryptographically correct"证书,绕过验证并获得未经授权的访问。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2004-1099

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2004-1099

登录查看更多情报信息。

Same Patch Batch · n/a · 2004-12-01 · 46 CVEs total

CVE-2004-1108Gentoo Gentoolkit 文件覆盖漏洞
CVE-2004-1111Cisco IOS DHCP 拒绝服务漏洞
CVE-2004-1113SQLgreyPostfixGreylistingService email地址 SQL注入漏洞
CVE-2004-1116mersenne.org GIMPS 本地权限提升漏洞
CVE-2004-1117chessbrain.net ChessBrain init 用户权限提升漏洞
CVE-2004-1118weonlydo WodFTPDLX WodFTPDLX.dll 缓冲区溢出漏洞
CVE-2004-1119Winamp in_cdda.dll 缓冲区溢出漏洞
CVE-2004-1120ProZilla 多个 缓冲区溢出漏洞
CVE-2004-1115Berkeley SETI@home 本地权限提升漏洞
CVE-2004-1109Kerio PersonalFirewall FWDRV.SYS 拒绝服务漏洞
CVE-2004-1110MtinkStatusMonitor epso 文件覆盖漏洞
CVE-2004-1107Gentoo Portage dispatch-conf 文件覆盖漏洞
CVE-2004-1106Gallery index.php 跨站脚本攻击漏洞
CVE-2004-1105Noterl ContivityVPNClient ErrorMessage 信息泄露漏洞
CVE-2004-1104Microsoft Internet Explorer HTML格式标签URI模糊漏洞
CVE-2004-1103Mcenter MailPost debug 信息泄露漏洞
CVE-2004-1102Mcenter MailPost ErrorMessage 信息泄露漏洞
CVE-2004-1101Mcenter MailPost mailpost.exe 多种安全漏洞
CVE-2004-1100mcenter MailPost mailpost.exe 跨站脚本攻击漏洞
CVE-2004-1098MIME-tools MIMEDefang 绕过病毒检测漏洞

Showing top 20 of 46 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2004-1099

No comments yet


Leave a comment