Cisco Router Web Setup (CRWS) Authentication Bypass Vulnerability
BID:18953
CVE-2006-3595 |Info
Cisco Router Web Setup (CRWS) Authentication Bypass Vulnerability
| Bugtraq ID: | 18953 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2006 12:00AM |
| Updated: | Jul 13 2006 09:43PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Cisco SOHO 97 0 Cisco SOHO 96 0 Cisco SOHO 91 0 Cisco SOHO 78 0 Cisco SOHO 77 H Cisco SOHO 77 0 Cisco SOHO 76 0 Cisco SOHO 71 0 Cisco CRWS 0 Cisco 837 0 Cisco 836 0 Cisco 831 0 Cisco 828 0 Cisco 827 H Cisco 827 0 Cisco 827 -v4 Cisco 826 0 Cisco 806 0 |
| Not Vulnerable: |
Cisco CRWS 2.2 build 31 |
Discussion
Cisco Router Web Setup (CRWS) Authentication Bypass Vulnerability
Cisco Router Web Setup (CRWS) is prone to a remote authentication-bypass vulnerability. This issue is due to the application's failure to ensure that remote web-based users are properly authenticated.
This issue allows remote attackers to gain administrative access to affected routers. This may aid them in further attacks.
CRWS for Cisco SOHO and Cisco 800 series routers with versions prior to 3.3.0 build 31 were identified as vulnerable to this issue.
This vulnerability is documented in Cisco Bug ID CSCsa78190.
Cisco Router Web Setup (CRWS) is prone to a remote authentication-bypass vulnerability. This issue is due to the application's failure to ensure that remote web-based users are properly authenticated.
This issue allows remote attackers to gain administrative access to affected routers. This may aid them in further attacks.
CRWS for Cisco SOHO and Cisco 800 series routers with versions prior to 3.3.0 build 31 were identified as vulnerable to this issue.
This vulnerability is documented in Cisco Bug ID CSCsa78190.
Exploit / POC
Cisco Router Web Setup (CRWS) Authentication Bypass Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
Cisco Router Web Setup (CRWS) Authentication Bypass Vulnerability
Solution:
The vendor released software upgrades to address this issue. Please see the references for details. The referenced advisory gives the steps required to address this issue, which may be required even when installing fixed software.
Solution:
The vendor released software upgrades to address this issue. Please see the references for details. The referenced advisory gives the steps required to address this issue, which may be required even when installing fixed software.
References
Cisco Router Web Setup (CRWS) Authentication Bypass Vulnerability
References:
References: