CVE-2006-3226
Summary
| CVE | CVE-2006-3226 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-26 16:05:00 UTC |
| Updated | 2018-10-18 16:46:00 UTC |
| Description | Cisco Secure Access Control Server (ACS) 4.x for Windows uses the client's IP address and the server's port number to grant access to an HTTP server port for an administration session, which allows remote attackers to bypass authentication via various methods, aka "ACS Weak Session Management Vulnerability." |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Secure Access Control Server | 4.0 | All | windows | All |
| Application | Cisco | Secure Access Control Server | 4.0.1 | All | windows | All |
| Application | Cisco | Secure Access Control Server | 4.0 | All | windows | All |
| Application | Cisco | Secure Access Control Server | 4.0.1 | All | windows | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Secure ACS Authentication Bypass Vulnerability | BID | www.securityfocus.com | |
| Cisco Response to: Cisco Secure ACS Weak Session Management Vulnerability [Cisco Secure Access Control Server for Windows] - Cisco Systems | CISCO | www.cisco.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Secunia - Advisories - Cisco Secure ACS Session Management Security Issue | SECUNIA | secunia.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| 26825 | OSVDB | www.osvdb.org | |
| SecurityTracker.com Archives - Cisco Secure Access Control Server Session Authentication Weakness Lets Remote Users Hijack Management Sessions | SECTRACK | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CXSecurity - IDS | SREASON | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.