{"api_version":"1","generated_at":"2026-07-23T10:42:46+00:00","cve":"CVE-2007-0058","urls":{"html":"https://cve.report/CVE-2007-0058","api":"https://cve.report/api/cve/CVE-2007-0058.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0058","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0058"},"summary":{"title":"CVE-2007-0058","description":"Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-01-04 22:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/23556","name":"http://secunia.com/advisories/23556","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Cisco Clean Access Predictable Snapshots Filename - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/0030","name":"http://www.vupen.com/english/advisories/2007/0030","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017465","name":"http://securitytracker.com/id?1017465","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Cisco Clean Access Lets Remote Users Access the Administrative Interface and Download Backup Files - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/32579","name":"http://www.osvdb.org/32579","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml","name":"http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco - Networking, Cloud, and Cybersecurity Solutions","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0058","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0058","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"58","vulnerable":"1","versionEndIncluding":"3.5.9","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"network_admission_control_manager_and_server_system_software","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"58","vulnerable":"1","versionEndIncluding":"3.6.1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"network_admission_control_manager_and_server_system_software","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:03:36.996Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"23556","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23556"},{"name":"32579","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/32579"},{"name":"ADV-2007-0030","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0030"},{"name":"20070103 Multiple Vulnerabilities in Cisco Clean Access","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml"},{"name":"1017465","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017465"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-06-15T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"23556","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23556"},{"name":"32579","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/32579"},{"name":"ADV-2007-0030","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0030"},{"name":"20070103 Multiple Vulnerabilities in Cisco Clean Access","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml"},{"name":"1017465","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017465"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-0058","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"23556","refsource":"SECUNIA","url":"http://secunia.com/advisories/23556"},{"name":"32579","refsource":"OSVDB","url":"http://www.osvdb.org/32579"},{"name":"ADV-2007-0030","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0030"},{"name":"20070103 Multiple Vulnerabilities in Cisco Clean Access","refsource":"CISCO","url":"http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml"},{"name":"1017465","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017465"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-0058","datePublished":"2007-01-04T22:00:00.000Z","dateReserved":"2007-01-04T00:00:00.000Z","dateUpdated":"2024-08-07T12:03:36.996Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-01-04 22:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:network_admission_control_manager_and_server_system_software:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5.0","versionEndIncluding":"3.5.9","matchCriteriaId":"A7A6B855-C210-4478-B97B-EFD2C05BD168"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:network_admission_control_manager_and_server_system_software:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6.0.0","versionEndIncluding":"3.6.1.1","matchCriteriaId":"CA5FD7EA-9D1F-417C-854A-D0D7650C1BC4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"58","Ordinal":"1","Title":"CVE-2007-0058","CVE":"CVE-2007-0058","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"58","Ordinal":"1","NoteData":"Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.","Type":"Description","Title":"CVE-2007-0058"},{"CveYear":"2007","CveId":"58","Ordinal":"2","NoteData":"2007-01-04","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"58","Ordinal":"3","NoteData":"2007-06-15","Type":"Other","Title":"Modified"}]}}}