{"api_version":"1","generated_at":"2026-07-23T10:01:35+00:00","cve":"CVE-2006-5660","urls":{"html":"https://cve.report/CVE-2006-5660","api":"https://cve.report/api/cve/CVE-2006-5660.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-5660","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-5660"},"summary":{"title":"CVE-2006-5660","description":"Cisco Security Agent Management Center (CSAMC) 5.1 before 5.1.0.79 does not properly handle certain LDAP error messages, which allows remote attackers to bypass authentication requirements via an empty password when using an external LDAP server.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-11-03 00:07:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/22684","name":"http://secunia.com/advisories/22684","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Security Agent LDAP Authentication Bypass - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/778648","name":"http://www.kb.cert.org/vuls/id/778648","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#778648","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017148","name":"http://securitytracker.com/id?1017148","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Security Agent Management Center May Grant Administrative Access to Remote Users - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/30169","name":"http://www.osvdb.org/30169","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.cisco.com/en/US/products/products_security_advisory09186a00807726f7.shtml","name":"http://www.cisco.com/en/US/products/products_security_advisory09186a00807726f7.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Cisco Security Advisory: Cisco Security Agent Management Center LDAP Administrator Authentication Bypass  [Products & Services] - Cisco Systems","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4308","name":"http://www.vupen.com/english/advisories/2006/4308","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29955","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29955","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/20852","name":"http://www.securityfocus.com/bid/20852","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Cisco Security Agent Management Center Authentication Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-5660","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-5660","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"5660","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"security_agent_management_center","cpe6":"5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T19:55:54.162Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"cisco-csamc-auth-bypass(29955)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29955"},{"name":"22684","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/22684"},{"name":"20061101 Cisco Security Agent Management Center LDAP Administrator Authentication Bypass","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/en/US/products/products_security_advisory09186a00807726f7.shtml"},{"name":"30169","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/30169"},{"name":"ADV-2006-4308","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4308"},{"name":"20852","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/20852"},{"name":"1017148","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017148"},{"name":"VU#778648","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/778648"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-11-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cisco Security Agent Management Center (CSAMC) 5.1 before 5.1.0.79 does not properly handle certain LDAP error messages, which allows remote attackers to bypass authentication requirements via an empty password when using an external LDAP server."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"cisco-csamc-auth-bypass(29955)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29955"},{"name":"22684","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/22684"},{"name":"20061101 Cisco Security Agent Management Center LDAP Administrator Authentication Bypass","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/en/US/products/products_security_advisory09186a00807726f7.shtml"},{"name":"30169","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/30169"},{"name":"ADV-2006-4308","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4308"},{"name":"20852","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/20852"},{"name":"1017148","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017148"},{"name":"VU#778648","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/778648"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-5660","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cisco Security Agent Management Center (CSAMC) 5.1 before 5.1.0.79 does not properly handle certain LDAP error messages, which allows remote attackers to bypass authentication requirements via an empty password when using an external LDAP server."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"cisco-csamc-auth-bypass(29955)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29955"},{"name":"22684","refsource":"SECUNIA","url":"http://secunia.com/advisories/22684"},{"name":"20061101 Cisco Security Agent Management Center LDAP Administrator Authentication Bypass","refsource":"CISCO","url":"http://www.cisco.com/en/US/products/products_security_advisory09186a00807726f7.shtml"},{"name":"30169","refsource":"OSVDB","url":"http://www.osvdb.org/30169"},{"name":"ADV-2006-4308","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4308"},{"name":"20852","refsource":"BID","url":"http://www.securityfocus.com/bid/20852"},{"name":"1017148","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017148"},{"name":"VU#778648","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/778648"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-5660","datePublished":"2006-11-03T00:00:00.000Z","dateReserved":"2006-11-02T00:00:00.000Z","dateUpdated":"2024-08-07T19:55:54.162Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-11-03 00:07:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:security_agent_management_center:5.1:*:*:*:*:*:*:*","matchCriteriaId":"916862A1-0475-4684-9C1D-DA62F6F44B2E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"5660","Ordinal":"1","Title":"CVE-2006-5660","CVE":"CVE-2006-5660","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"5660","Ordinal":"1","NoteData":"Cisco Security Agent Management Center (CSAMC) 5.1 before 5.1.0.79 does not properly handle certain LDAP error messages, which allows remote attackers to bypass authentication requirements via an empty password when using an external LDAP server.","Type":"Description","Title":"CVE-2006-5660"},{"CveYear":"2006","CveId":"5660","Ordinal":"2","NoteData":"2006-11-02","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"5660","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}