CVE-2006-4430
Summary
| CVE | CVE-2006-4430 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-29 00:04:00 UTC |
| Updated | 2018-10-30 16:26:00 UTC |
| Description | The Cisco Network Admission Control (NAC) 3.6.4.1 and earlier allows remote attackers to prevent installation of the Cisco Clean Access (CCA) Agent and bypass local and remote protection mechanisms by modifying (1) the HTTP User-Agent header or (2) the behavior of the TCP/IP stack. NOTE: the vendor has disputed the severity of this issue, stating that users cannot bypass authentication mechanisms. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Cisco Security Notice: Response to BugTraq - Cisco Clean Access Agent (Perfigo) Bypass [Cisco NAC Appliance (Clean Access)] - Cisco Systems | CISCO | www.cisco.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| RE: Cisco Clean Access Agent (Perfigo) bypass | BUGTRAQ | archive.cert.uni-stuttgart.de | |
| Cisco Security Response: NAC Agent Installation Bypass [Cisco NAC Appliance (Clean Access)] - Cisco Systems | CISCO | www.cisco.com | |
| Cisco NAC Agent Installation Security Bypass Vulnerability | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.