Mark Laing discovered that LXDs PKI mode, until version 5.21.2, could be bypassed if the clients certificate was present in the trust store.
Weakness
The product does not validate, or incorrectly validates, a certificate.
Potential Mitigations
References