PT-2006-1813 · Cisco · Cisco Anomaly Detection/Mitigation

Gerrit Wenig

·

Published

2006-02-18

·

Updated

2017-07-20

·

CVE-2006-0764

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco Anomaly Detection and Mitigation software versions 5.0(1) and 5.0(3)
Description The issue concerns the Authentication, Authorization, and Accounting (AAA) capability. When running with an incomplete TACACS+ configuration without a "tacacs-server host" command, it allows remote attackers to bypass authentication and gain privileges.
Recommendations For version 5.0(1), ensure a complete TACACS+ configuration, including the "tacacs-server host" command, to prevent authentication bypass. For version 5.0(3), ensure a complete TACACS+ configuration, including the "tacacs-server host" command, to prevent authentication bypass.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0764

Affected Products

Cisco Anomaly Detection/Mitigation