PT-2006-5231 · Cisco · Cisco Clean Access Agent+1

Published

2006-08-29

·

Updated

2018-10-30

·

CVE-2006-4430

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Network Admission Control (NAC) versions 3.6.4.1 and earlier
Description The issue allows remote attackers to prevent installation of the Cisco Clean Access (CCA) Agent and potentially bypass protection mechanisms. This can be achieved by modifying the User-Agent header or the behavior of the TCP/IP stack. The vendor has disputed the severity of this issue, stating that users cannot bypass authentication mechanisms.
Recommendations For Cisco Network Admission Control (NAC) versions 3.6.4.1 and earlier, consider restricting modifications to the User-Agent header and monitoring TCP/IP stack behavior to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4430

Affected Products

Cisco Clean Access Agent
Cisco Network Admission Control