MEDIUM
The Cisco Network Admission Control (NAC) 3.6.4.1 and earlier allows remote attackers to prevent installation of the Cisco Clean Access (CCA) Agent and bypass local and remote protection mechanisms by modifying (1) the HTTP User-Agent header or (2) the behavior of the TCP/IP stack
Published Aug 29, 2006
5.0
MEDIUMCVSS 2.0
EPSS 1.95%
Description
The Cisco Network Admission Control (NAC) 3.6.4.1 and earlier allows remote attackers to prevent installation of the Cisco Clean Access (CCA) Agent and bypass local and remote protection mechanisms by modifying (1) the HTTP User-Agent header or (2) the behavior of the TCP/IP stack. NOTE: the vendor has disputed the severity of this issue, stating that users cannot bypass authentication mechanisms.
Affected products
No data.
OR
- ≤ 3.6.4.1
- 3.3
- 3.3.1
- 3.3.2
- 3.3.3
- 3.3.4
- 3.3.5
- 3.3.6
- 3.3.7
- 3.3.8
- 3.3.9
- 3.4
- 3.4.1
- 3.4.2
- 3.4.3
- 3.4.4
- 3.4.5
- 3.5
- 3.5\(9\)
- 3.5.1
- 3.5.2
- 3.5.3
- 3.5.4
- 3.5.5
- 3.6.0.1
- 3.6.4.0.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (8)
- http://archive.cert.uni-stuttgart.de/archive/bugtraq/2005/08/msg00200.html mailing-listx_refsource_BUGTRAQ
- http://www.cisco.com/en/US/products/ps6128/products_security_notice09186a00804fa82b.html vendor-advisoryx_refsource_CISCO
- http://www.cisco.com/en/US/products/ps6128/tsd_products_security_response09186a008071d609.html vendor-advisoryx_refsource_CISCO
- http://www.securityfocus.com/archive/1/408603/30/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/444424/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/444501/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/444737/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/19726 vdb-entryx_refsource_BID
| Link | Providers | Tags |
|---|---|---|
| http://archive.cert.uni-stuttgart.de/archive/bugtraq/2005/08/msg00200.html | mailing-listx_refsource_BUGTRAQ | |
| http://www.cisco.com/en/US/products/ps6128/products_security_notice09186a00804fa82b.html | vendor-advisoryx_refsource_CISCO | |
| http://www.cisco.com/en/US/products/ps6128/tsd_products_security_response09186a008071d609.html | vendor-advisoryx_refsource_CISCO | |
| http://www.securityfocus.com/archive/1/408603/30/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/archive/1/444424/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/archive/1/444501/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/archive/1/444737/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/19726 | vdb-entryx_refsource_BID |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 29, 2006
Updated Aug 7, 2024
Reserved Aug 28, 2006
Link CVE-2006-4430
CISA Vulnrichment
Updated n/a