VDB

CVE-2007-1068

CVE-2007-1068 PUBLISHED CVSS 7.199999809265137 HIGH

The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client store transmitted authentication credentials in plaintext log files, which allows local users to obtain sensitive information by reading these files, aka CSCsg34423.

EPSS 0.09% · 26.3th percentile

Risk Scores

CVSS 2.0
7.199999809265137
EPSS Score
0.09%
26.3th percentile

Affected Products

VendorProductVersions
ciscosecurity_agent5.1, 5.0
meetinghouseaegis_secureconnect_clientwindows_platform
ciscotrust_agent2.1, 2.0, 2.0.1
ciscosecure_services_client4.0.51, 4.0, 4.0.5
n/an/an/a

Timeline

  • Feb 21, 2007 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 1, 2022 CVE Updated
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›