CVE Vulnerabilities

CVE-2006-3291

Published: Jun 28, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the Local User List Only (Individual Passwords) setting, which removes all security and password configurations and allows remote attackers to access the system.

Affected Software

NameVendorStart VersionEnd Version
IosCisco12.3(8)ja (including)12.3(8)ja (including)
IosCisco12.3(8)ja1 (including)12.3(8)ja1 (including)

References