Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Gerrit Wenig

Researcher fromVerizon Business
#48687of 53,635
5.1Total CVSS
Vulnerabilities · 1
PT-2006-1813
5.1
2006-02-18
Cisco · Cisco Anomaly Detection/Mitigation · CVE-2006-0764
**Name of the Vulnerable Software and Affected Versions** Cisco Anomaly Detection and Mitigation software versions 5.0(1) and 5.0(3) **Description** The issue concerns the Authentication, Authorization, and Accounting (AAA) capability. When running with an incomplete TACACS+ configuration without a "tacacs-server host" command, it allows remote attackers to bypass authentication and gain privileges. **Recommendations** For version 5.0(1), ensure a complete TACACS+ configuration, including the "tacacs-server host" command, to prevent authentication bypass. For version 5.0(3), ensure a complete TACACS+ configuration, including the "tacacs-server host" command, to prevent authentication bypass.