CVE-2006-4313
published 2006-08-23CVE-2006-4313: Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers to execute…
PriorityP336medium5CVSS 2.0
AVNACLAuNCNIPAN
EXPLOIT
EPSS
12.10%
95.7th percentile
Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers to execute the (1) CWD, (2) MKD, (3) CDUP, (4) RNFR, (5) SIZE, and (6) RMD FTP commands to modify files or create and delete directories via unknown vectors.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | vpn_3000_concentrator_ftp_management | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor FTP sessions to Cisco VPN 3000 concentrators for unauthenticated issuance of CWD, RNFR, MKD, RMD, SIZE, or CDUP commands — successful execution of these commands prior to authentication is a strong indicator of exploitation. ↗
- →Alert on FTP directory creation (MKD) or deletion (RMD) commands issued against Cisco VPN 3000 concentrators, especially when not preceded by a successful authentication exchange. ↗
- →Exploitation is only possible when FTP file management is enabled on the concentrator; detect by checking for open FTP service on VPN 3000 devices and correlating with unauthenticated command sequences. ↗
- →Watch for anomalous CWD command sequences on FTP sessions to VPN 3000 devices; the vulnerability also involves memory leak behavior triggered by repeated CWD commands. ↗
- ·The vulnerability is only exploitable when FTP file management is explicitly enabled on the Cisco VPN 3000 concentrator. Disabling FTP management is a valid workaround. ↗
- ·The vulnerability does not permit file exfiltration or upload; only directory manipulation and file deletion are possible via the unauthenticated FTP command bypass. ↗
- ·Affected versions span multiple branches: VPN 3000 series before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F. Ensure patched firmware is applied across all branches. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco VPN 3000 Concentrator FTP Management Vulnerabilities
vendor_cisco·2006-08-23·CVSS 7.0
CVE-2006-4313 [HIGH] Cisco VPN 3000 Concentrator FTP Management Vulnerabilities
Cisco VPN 3000 Concentrator FTP Management Vulnerabilities
The Cisco VPN 3000 series concentrators are affected by two
vulnerabilities when file management via File Transfer Protocol (FTP) is
enabled that could allow authenticated or unauthenticated attackers to execute
certain FTP commands and delete files on the concentrator.
None of the vulnerabilities allows unauthorized users to transfer
files from or to the concentrator.
Cisco has made free software available to address these
vulnerabilities for affected customers. There are workarounds available to
mitigate these vulnerabilities as well.
This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20060823-vpn3k.
Cisco
Cisco VPN 3000 Concentrator FTP Management Vulnerabilities
vendor_cisco
CVE-2006-4313 Cisco VPN 3000 Concentrator FTP Management Vulnerabilities
CVE-2006-4313: Cisco VPN 3000 Concentrator FTP Management Vulnerabilities
The Cisco VPN 3000 series concentrators are affected by two vulnerabilities when file management via File Transfer Protocol (FTP) is enabled that could allow authenticated or unauthenticated attackers to execute certain FTP commands and delete files on the concentrator. None of the vulnerabilities allows unauthorized users to transfer files from or to the concentrator. Cisco has made free software available to address these vulnerabilities for affected customers. There are
Bug IDs: CSCse10733, CSCse10753
GHSA
GHSA-ghgm-j4vc-66gp: Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4
ghsa_unreviewed·2022-05-01
CVE-2006-4313 [MEDIUM] GHSA-ghgm-j4vc-66gp: Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4
Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers to execute the (1) CWD, (2) MKD, (3) CDUP, (4) RNFR, (5) SIZE, and (6) RMD FTP commands to modify files or create and delete directories via unknown vectors.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/21617http://securitytracker.com/id?1016737http://www.cisco.com/warp/public/707/cisco-sa-20060823-vpn3k.shtmlhttp://www.osvdb.org/28138http://www.osvdb.org/28139http://www.securityfocus.com/bid/19680http://www.vupen.com/english/advisories/2006/3368https://exchange.xforce.ibmcloud.com/vulnerabilities/28539http://secunia.com/advisories/21617http://securitytracker.com/id?1016737http://www.cisco.com/warp/public/707/cisco-sa-20060823-vpn3k.shtmlhttp://www.osvdb.org/28138http://www.osvdb.org/28139http://www.securityfocus.com/bid/19680http://www.vupen.com/english/advisories/2006/3368https://exchange.xforce.ibmcloud.com/vulnerabilities/28539
2006-08-23
Published