CVE-2006-3291
Summary
| CVE | CVE-2006-3291 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-28 23:05:00 UTC |
| Updated | 2017-07-20 01:32:00 UTC |
| Description | The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the "Local User List Only (Individual Passwords)" setting, which removes all security and password configurations and allows remote attackers to access the system. |
Risk And Classification
Problem Types: CWE-16
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Ios | 12.3(8)ja | All | All | All |
| Operating System | Cisco | Ios | 12.3(8)ja1 | All | All | All |
| Operating System | Cisco | Ios | 12.3\(8\)ja | All | All | All |
| Operating System | Cisco | Ios | 12.3\(8\)ja1 | All | All | All |
| Operating System | Cisco | Ios | 12.3\(8\)ja | All | All | All |
| Operating System | Cisco | Ios | 12.3\(8\)ja1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| 26878 | OSVDB | www.osvdb.org | |
| Cisco Access Point Web Interface Authorization Bypass Vulnerability | BID | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| SecurityTracker.com Archives - Cisco Access Point Configuration Error May Let Remote Users Gain Administrative Access | SECTRACK | securitytracker.com | |
| Cisco Wireless Access Point Web Management Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | |
| US-CERT Vulnerability Note VU#544484 | CERT-VN | www.kb.cert.org | US Government Resource |
| Cisco - Networking, Cloud, and Cybersecurity Solutions | CISCO | www.cisco.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.