CVE-2004-1099: Critical severity Cisco Secure Acs Solution Engine vulnerability
Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1099?
CVE-2004-1099 has a critical severity level due to its potential to allow remote attackers to bypass authentication.
How do I fix CVE-2004-1099?
To fix CVE-2004-1099, update your Cisco Secure Access Control Server to the latest version that addresses this vulnerability.
What systems are affected by CVE-2004-1099?
CVE-2004-1099 affects Cisco Secure Access Control Server version 3.3(1), 3.3.1, and Cisco Secure ACS Solution Engine.
Can CVE-2004-1099 be exploited without user interaction?
Yes, CVE-2004-1099 can be exploited remotely without user interaction, making it especially dangerous.
What type of vulnerability is CVE-2004-1099?
CVE-2004-1099 is an authentication bypass vulnerability related to improper handling of expired or untrusted certificates during EAP-TLS protocol.