PT-2006-4742 · Neoscale Systems · Neoscale Systems Cryptostor
Will Dormann
·
Published
2006-12-19
·
Updated
2011-03-08
·
CVE-2006-3896
CVSS v2.0
4.9
Medium
| Vector | AV:A/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NeoScale Systems CryptoStor 700 series appliance versions prior to 2.6
Description
The issue allows remote attackers to bypass smartcard authentication and gain access by presenting a valid username and password if they can disable ActiveX, due to the reliance on client-side ActiveX code for smartcard authentication.
Recommendations
For versions prior to 2.6, consider disabling the use of ActiveX for smartcard authentication as a temporary workaround until a patch is available. Restrict access to the appliance to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Neoscale Systems Cryptostor