Vulnerabilities (CVE)

Filtered by vendor Uninett Subscribe
Filtered by product Radsecproxy
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-4523 1 Uninett 1 Radsecproxy 2013-01-30 6.4 MEDIUM N/A
radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients.
CVE-2012-4566 1 Uninett 1 Radsecproxy 2012-11-20 6.4 MEDIUM N/A
The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients, a different vulnerability than CVE-2012-4523.