The NeoScale Systems CryptoStor 700 series appliance before 2.6 relies on client-side ActiveX code for smartcard authentication, which allows remote attackers to bypass smartcard authentication, and gain access if able to present a valid username and password, by disabling ActiveX.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2006/5063 | vdb entry |
http://secunia.com/advisories/23430 | third party advisory patch vendor advisory |
http://www.kb.cert.org/vuls/id/339004 | us government resource third party advisory patch |
http://securitytracker.com/id?1017396 | vdb entry |
http://www.securityfocus.com/bid/21652 | vdb entry |