PT-2006-4121 · Cisco · Cisco Secure Access Control Server
Darren Bounds
·
Published
2006-06-26
·
Updated
2018-10-18
·
CVE-2006-3226
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco Secure Access Control Server (ACS) version 4.x
Description
The issue allows remote attackers to bypass authentication via various methods by utilizing the client's IP address and the server's port number to grant access to an HTTP server port for an administration session.
Recommendations
For Cisco Secure Access Control Server (ACS) version 4.x, consider restricting access to the administration session to minimize the risk of exploitation until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Secure Access Control Server