CVE-2012-4523
radsecproxy - SSL certificate verification weakness
EPSS 1.8%
Description
radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients.
How to fix CVE-2012-4523
To remediate CVE-2012-4523, upgrade the affected package to a fixed version below.
- Debian/radsecproxy—upgrade to 1.6.2-1 or later
- Debian/radsecproxy—upgrade to 1.4-1+squeeze1 or later
Is CVE-2012-4523 being exploited?
Low — EPSS is 1.8%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.6.2-1
- from 0, < 1.4-1+squeeze1