CVE Vulnerabilities

CVE-2006-0764

Published: Feb 18, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a tacacs-server host command, allows remote attackers to bypass authentication and gain privileges, aka Bug ID CSCsd21455.

Affected Software

NameVendorStart VersionEnd Version
Anomaly_guard_moduleCisco5.0(1) (including)5.0(1) (including)
Anomaly_guard_moduleCisco5.0(3) (including)5.0(3) (including)
GuardCisco5.0(1) (including)5.0(1) (including)
GuardCisco5.0(3) (including)5.0(3) (including)
Traffic_anomaly_detector_moduleCisco5.0(1) (including)5.0(1) (including)
Traffic_anomaly_detector_moduleCisco5.0(3) (including)5.0(3) (including)

References