The NeoScale Systems CryptoStor 700 series appliance before 2.6 relies on client-side ActiveX code for smartcard authentication, which allows remote attackers to bypass smartcard authentication, and gain access if able to present a valid username and password, by disabling ActiveX.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cryptostor_tape_700 | Neoscale_systems | * | * |