cbcvebase.
CVE-2006-4313
published 2006-08-23

CVE-2006-4313: Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers to execute…

PriorityP336medium5CVSS 2.0
AVNACLAuNCNIPAN
EXPLOIT
EPSS
12.10%
95.7th percentile
Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers to execute the (1) CWD, (2) MKD, (3) CDUP, (4) RNFR, (5) SIZE, and (6) RMD FTP commands to modify files or create and delete directories via unknown vectors.

Affected

12 ranges
VendorProductVersion rangeFixed in
ciscovpn_3000_concentrator_ftp_management
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software
ciscovpn_3000_concentrator_series_software

Detection & IOCsextracted from sources · hover to see the quote

commandCWD
commandRNFR
commandMKD
commandRMD
commandSIZE
commandCDUP
  • Monitor FTP sessions to Cisco VPN 3000 concentrators for unauthenticated issuance of CWD, RNFR, MKD, RMD, SIZE, or CDUP commands — successful execution of these commands prior to authentication is a strong indicator of exploitation.
  • Alert on FTP directory creation (MKD) or deletion (RMD) commands issued against Cisco VPN 3000 concentrators, especially when not preceded by a successful authentication exchange.
  • Exploitation is only possible when FTP file management is enabled on the concentrator; detect by checking for open FTP service on VPN 3000 devices and correlating with unauthenticated command sequences.
  • Watch for anomalous CWD command sequences on FTP sessions to VPN 3000 devices; the vulnerability also involves memory leak behavior triggered by repeated CWD commands.
  • ·The vulnerability is only exploitable when FTP file management is explicitly enabled on the Cisco VPN 3000 concentrator. Disabling FTP management is a valid workaround.
  • ·The vulnerability does not permit file exfiltration or upload; only directory manipulation and file deletion are possible via the unauthenticated FTP command bypass.
  • ·Affected versions span multiple branches: VPN 3000 series before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F. Ensure patched firmware is applied across all branches.

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.