Authentication Bypass in Microsoft ISA Server 2006
CVE-2009-1135
Currently unrated
Summary
The vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2006 allows remote attackers to exploit the Radius OTP feature when HTTP-Basic authentication is enabled. This enables an attacker to gain unauthorized access to network resources and potentially control over arbitrary user accounts. As a result, sensitive web pages behind the ISA Server may be exposed, leading to serious security risks.
References
EPSS Score
41% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved