PT-2006-5231 · Cisco · Cisco Clean Access Agent+1
Published
2006-08-29
·
Updated
2018-10-30
·
CVE-2006-4430
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Network Admission Control (NAC) versions 3.6.4.1 and earlier
Description
The issue allows remote attackers to prevent installation of the Cisco Clean Access (CCA) Agent and potentially bypass protection mechanisms. This can be achieved by modifying the
User-Agent header or the behavior of the TCP/IP stack. The vendor has disputed the severity of this issue, stating that users cannot bypass authentication mechanisms.Recommendations
For Cisco Network Admission Control (NAC) versions 3.6.4.1 and earlier, consider restricting modifications to the
User-Agent header and monitoring TCP/IP stack behavior to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Clean Access Agent
Cisco Network Admission Control