CVE-2007-1068
Summary
| CVE | CVE-2007-1068 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-02-22 01:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client store transmitted authentication credentials in plaintext log files, which allows local users to obtain sensitive information by reading these files, aka CSCsg34423. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Secure Services Client | 4.0 | All | All | All |
| Application | Cisco | Secure Services Client | 4.0.5 | All | All | All |
| Application | Cisco | Secure Services Client | 4.0.51 | All | All | All |
| Application | Cisco | Security Agent | 5.0 | All | All | All |
| Application | Cisco | Security Agent | 5.1 | All | All | All |
| Application | Cisco | Trust Agent | 1.0 | All | All | All |
| Application | Cisco | Trust Agent | 2.0 | All | All | All |
| Application | Cisco | Trust Agent | 2.0.1 | All | All | All |
| Application | Cisco | Trust Agent | 2.1 | All | All | All |
| Application | Meetinghouse | Aegis Secureconnect Client | windows_platform | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker: Cisco Secure Services Client Lets Local Users Gain System Privileges and Also View Passwords | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Cisco Secure Services Client Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| osvdb.org/33046 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco 802.1X Authentication Deployment Products Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker: Cisco Trust Agent Lets Local Users Gain System Privileges and Also View Passwords | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Cisco - Networking, Cloud, and Cybersecurity Solutions | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.