Vulnerability Name: | CVE-2006-3595 (CCN-27688) | ||||||||
Assigned: | 2006-07-12 | ||||||||
Published: | 2006-07-12 | ||||||||
Updated: | 2017-10-11 | ||||||||
Summary: | The default configuration of IOS HTTP server in Cisco Router Web Setup (CRWS) before 3.3.0 build 31 does not require credentials, which allows remote attackers to access the server with arbitrary privilege levels, aka bug CSCsa78190. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-3595 Source: CCN Type: SA21028 Cisco Router Web Setup Insecure Default Cisco IOS Configuration Source: SECUNIA Type: Vendor Advisory 21028 Source: CCN Type: SECTRACK ID: 1016476 Cisco Router Web Setup Tool Uses an Unsafe IOS Router Configuration By Default Source: SECTRACK Type: UNKNOWN 1016476 Source: CCN Type: cisco-sa-20060712-crws Cisco Security Advisory: Cisco Router Web Setup Ships with Insecure Default IOS Configuration Source: CISCO Type: Patch 20060712 Cisco Router Web Setup Ships with Insecure Default IOS Configuration Source: CCN Type: US-CERT VU#205225 Cisco Router Web Setup (CRWS) contains an insecure default IOS configuration Source: CERT-VN Type: US Government Resource VU#205225 Source: OSVDB Type: UNKNOWN 27159 Source: CCN Type: OSVDB ID: 27159 Cisco Router Web Setup (CRWS) Default Configuration Authentication Bypass Source: BID Type: UNKNOWN 18953 Source: CCN Type: BID-18953 Cisco Router Web Setup (CRWS) Authentication Bypass Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-2773 Source: XF Type: UNKNOWN cisco-crws-command-execution(27688) Source: XF Type: UNKNOWN cisco-crws-command-execution(27688) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:5826 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |