Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2006-3291 | First vendor Publication | 2006-06-28 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the "Local User List Only (Individual Passwords)" setting, which removes all security and password configurations and allows remote attackers to access the system. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3291 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-16 | Configuration |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 2 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
26878 | Cisco Wireless Access Point Local User List Only Configuration Weakness Authe... Cisco Wireless Access Point contains a flaw that may allow a malicious user to gain unauthorized administrative access. The issue is triggered when the 'Local User List Only' mode is turned on, which removes all security and password configurations. It is possible that the flaw may allow remote users to access the system resulting in a loss of confidentiality. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-09-01 | Name : The remote device is missing a vendor-supplied security patch. File : cisco-sa-20060628-aphttp.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:20:07 |
|
2024-11-28 12:09:21 |
|
2021-05-04 12:04:14 |
|
2021-04-22 01:04:52 |
|
2020-05-23 00:18:01 |
|
2017-07-20 09:23:42 |
|
2016-06-28 15:51:16 |
|
2016-04-26 14:48:11 |
|
2014-02-17 10:36:16 |
|
2013-05-11 11:01:38 |
|