CVE-2007-1068
Last modified
CVE-2007-1068 is a vulnerability of currently unknown severity. The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client store transmitted authentication credentials in plaintext log files, which allows local users to obtain sensitive information by reading these files, aka CSCsg34423.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client store transmitted authentication credentials in plaintext log files, which allows local users to obtain sensitive information by reading these files, aka CSCsg34423.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Secure Services Client | 4.0 |
| Cisco | Secure Services Client | 4.0.5 |
| Cisco | Secure Services Client | 4.0.51 |
| Cisco | Security Agent | 5.0 |
| Cisco | Security Agent | 5.1 |
| Cisco | Trust Agent | 1.0 |
| Cisco | Trust Agent | 2.0 |
| Cisco | Trust Agent | 2.0.1 |
| Cisco | Trust Agent | 2.1 |
| Meetinghouse | Aegis Secureconnect Client | windows_platform |
References
- http://secunia.com/advisories/24258Vendor Advisory
- http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/0690Vendor Advisory
- http://secunia.com/advisories/24258Vendor Advisory
- http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/0690Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1068?
How severe is CVE-2007-1068?
How do I fix CVE-2007-1068?
Are you affected by CVE-2007-1068?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
