Vulnerabilities
Vulnerable Software
Cisco:  >> Trust Agent  >> 1  Security Vulnerabilities
Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a user notification message after posture validation.
CVSS Score
7.2
EPSS Score
0.001
Published
2007-06-12
Cisco Secure ACS does not require authentication when Cisco Trust Agent (CTA) transmits posture information, which might allow remote attackers to gain network access via a spoofed Network Endpoint Assessment posture, aka "NACATTACK." NOTE: this attack might be limited to authenticated users and devices.
CVSS Score
7.5
EPSS Score
0.007
Published
2007-04-02
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not properly parse commands, which allows local users to gain privileges via unspecified vectors, aka CSCsh30624.
CVSS Score
7.2
EPSS Score
0.001
Published
2007-02-22


Contact Us

Shodan ® - All rights reserved