CVE-2006-3291
published 2006-06-28CVE-2006-3291: The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed…
critical9.3CVSS 3.1
AVNACMAuNCCICAC
The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the "Local User List Only (Individual Passwords)" setting, which removes all security and password configurations and allows remote attackers to access the system.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
GHSA
GHSA-3j47-5x58-8672: The web interface on Cisco IOS 12
ghsa_unreviewed·2022-05-01
CVE-2006-3291 [HIGH] GHSA-3j47-5x58-8672: The web interface on Cisco IOS 12
The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the "Local User List Only (Individual Passwords)" setting, which removes all security and password configurations and allows remote attackers to access the system.
Cisco
Access Point Web-browser Interface Vulnerability
vendor_cisco·2006-06-28
CVE-2006-3291 Access Point Web-browser Interface Vulnerability
Access Point Web-browser Interface Vulnerability
The Cisco web-browser interface for Cisco access points and Cisco 3200
Series Wireless Mobile Interface Card (WMIC), contains a vulnerability that
could, under certain circumstances, remove the default security configuration
from the managed access point and allow administrative access without
validation of administrative user credentials.
Cisco has made free software available to address this vulnerability
for affected customers. There are workarounds available to mitigate the effects
of this vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20060628-ap.
Cisco
Access Point Web-browser Interface Vulnerability
vendor_cisco
CVE-2006-3291 Access Point Web-browser Interface Vulnerability
CVE-2006-3291: Access Point Web-browser Interface Vulnerability
The Cisco web-browser interface for Cisco access points and Cisco 3200 Series Wireless Mobile Interface Card (WMIC), contains a vulnerability that could, under certain circumstances, remove the default security configuration from the managed access point and allow administrative access without validation of administrative user credentials. Cisco has made free software available to address this vulnerability for affected customers. There are
Bug IDs: CSCsd67403, CSCsf18032, CSCsd67403
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/20860http://securitytracker.com/id?1016399http://www.cisco.com/warp/public/707/cisco-sa-20060628-ap.shtmlhttp://www.kb.cert.org/vuls/id/544484http://www.osvdb.org/26878http://www.securityfocus.com/bid/18704http://www.vupen.com/english/advisories/2006/2584https://exchange.xforce.ibmcloud.com/vulnerabilities/27437http://secunia.com/advisories/20860http://securitytracker.com/id?1016399http://www.cisco.com/warp/public/707/cisco-sa-20060628-ap.shtmlhttp://www.kb.cert.org/vuls/id/544484http://www.osvdb.org/26878http://www.securityfocus.com/bid/18704http://www.vupen.com/english/advisories/2006/2584https://exchange.xforce.ibmcloud.com/vulnerabilities/27437
2006-06-28
Published