Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Cisco VPN 3000 Series Concentrator Certificate Credential Disclosure Vulnerability

Cisco VPN 3000 series concentrators will disclose the certificate password in the Certificate Management web page source code. This may enable an administrative user to gain unauthorized access to the Certificate Management interface.

This would only be an issue in circumstances where the policy of an organization using the device restricts certificate management privileges to particular administrative users.







 

Privacy Statement
Copyright 2008, SecurityFocus