CVE-2010-4685

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
07/01/2011
Last modified:
11/04/2025

Description

Cisco IOS before 15.0(1)XA1 does not clear the public key cache upon a change to a certificate map, which allows remote authenticated users to bypass a certificate ban by connecting with a banned certificate that had previously been valid, aka Bug ID CSCta79031.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* 15.0\(1\)xa1 (excluding)