CVE-2006-0561
Summary
| CVE | CVE-2006-0561 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-05-10 02:14:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the master key in the registry with insecure permissions, which allows local users and remote administrators to decrypt the passwords by using Microsoft's cryptographic API functions to obtain the plaintext version of the master key. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS: 0.000490000 probability, percentile 0.148810000 (date 2026-04-20)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Secure Access Control Server | 3.0 | All | windows_nt | All |
| Application | Cisco | Secure Access Control Server | 3.0.1 | All | windows_nt | All |
| Application | Cisco | Secure Access Control Server | 3.0.3 | All | windows_nt | All |
| Application | Cisco | Secure Access Control Server | 3.1 | All | windows_nt | All |
| Application | Cisco | Secure Access Control Server | 3.1.1 | All | windows_nt | All |
| Application | Cisco | Secure Access Control Server | 3.2 | All | windows_nt | All |
| Application | Cisco | Secure Access Control Server | 3.2 | All | windows_server | All |
| Application | Cisco | Secure Access Control Server | 3.3 | All | windows_nt | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| symantec.com has moved to broadcom.com | af854a3a-2127-422b-91ae-364da2661108 | www.symantec.com | Patch, Vendor Advisory |
| Cisco Secure ACS Insecure Password Storage Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco - Networking, Cloud, and Cybersecurity Solutions | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Patch |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| www.osvdb.org/25892 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| SecurityTracker.com Archives - Cisco Secure ACS May Disclose Administrator Passwords to Local or Remote Authenticated Users | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.