PT-2006-1623 · Microsoft+1 · Windows+1

Publicado

2006-05-09

·

Atualizado

2017-07-20

·

CVE-2006-0561

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Secure Access Control Server (ACS) version 3.x for Windows
Description The issue concerns the storage of ACS administrator passwords and the master key in the registry with insecure permissions. This allows local users and remote administrators to decrypt the passwords by using Microsoft's cryptographic API functions to obtain the plaintext version of the master key.
Recommendations For Cisco Secure Access Control Server (ACS) version 3.x for Windows, consider restricting access to the registry to minimize the risk of exploitation. As a temporary workaround, limit the privileges of local users and remote administrators to reduce the potential for unauthorized access to the master key.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0561

Produtos afetados

Cisco Secure Access Control Server
Windows