CVE-2007-1065
published 2007-02-22CVE-2007-1065: Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and…
PriorityP419medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.30%
21.7th percentile
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client allows local users to gain SYSTEM privileges via unspecified vectors in the supplicant, aka CSCsf15836.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure_services_client | — | — |
| cisco | secure_services_client | — | — |
| cisco | secure_services_client | — | — |
| cisco | security_agent | — | — |
| cisco | security_agent | — | — |
| cisco | trust_agent | — | — |
| cisco | trust_agent | — | — |
| cisco | trust_agent | — | — |
| cisco | trust_agent | — | — |
| meetinghouse | aegis_secureconnect_client | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in 802.1X Supplicant
vendor_cisco·2007-02-21·CVSS 7.0
CVE-2007-1064 [HIGH] CWE-200 Multiple Vulnerabilities in 802.1X Supplicant
Multiple Vulnerabilities in 802.1X Supplicant
The Cisco Secure Services Client (CSSC) is a software client that
enables customers to deploy a single authentication framework using the 802.1X
authentication standard across multiple device types to access both wired and
wireless networks. A lightweight version of the CSSC client is also a component
of the Cisco Trust Agent (CTA) within the Cisco Network Admission Control (NAC)
Framework solution.
These products are affected by multiple vulnerabilities including
privilege escalations and information disclosure.
Cisco Security Agent (CSA) bundle versions 5.0 and 5.1 included Cisco
Trust Agent software within the bundle. Customers who have deployed CTA as part
of their CSA client package may be vulnerable if the version of CTA included is
a
Cisco
Multiple Vulnerabilities in 802.1X Supplicant
vendor_cisco
CVE-2007-1065 Multiple Vulnerabilities in 802.1X Supplicant
CVE-2007-1065: Multiple Vulnerabilities in 802.1X Supplicant
The Cisco Secure Services Client (CSSC) is a software client that enables customers to deploy a single authentication framework using the 802.1X authentication standard across multiple device types to access both wired and wireless networks. A lightweight version of the CSSC client is also a component of the Cisco Trust Agent (CTA) within the Cisco Network Admission Control (NAC) Framework solution. These products are affected by multiple vulnerabilities including privilege escalations and information disclosure. Cisco Security Agent (CSA) bundle versions 5.0 and 5.1 included Cisco Trust Agent software within the bundle. Customers who have deployed CTA as part of their CSA client package may be vulnerable if the version of CTA in
GHSA
GHSA-gfh7-q337-r38v: Cisco Secure Services Client (CSSC) 4
ghsa_unreviewed·2022-05-01
CVE-2007-1065 [MEDIUM] GHSA-gfh7-q337-r38v: Cisco Secure Services Client (CSSC) 4
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client allows local users to gain SYSTEM privileges via unspecified vectors in the supplicant, aka CSCsf15836.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/33048http://secunia.com/advisories/24258http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtmlhttp://www.securityfocus.com/bid/22648http://www.securitytracker.com/id?1017683http://www.securitytracker.com/id?1017684http://www.vupen.com/english/advisories/2007/0690https://exchange.xforce.ibmcloud.com/vulnerabilities/32622http://osvdb.org/33048http://secunia.com/advisories/24258http://www.cisco.com/warp/public/707/cisco-sa-20070221-supplicant.shtmlhttp://www.securityfocus.com/bid/22648http://www.securitytracker.com/id?1017683http://www.securitytracker.com/id?1017684http://www.vupen.com/english/advisories/2007/0690https://exchange.xforce.ibmcloud.com/vulnerabilities/32622
2007-02-22
Published