CVE-2006-4950
Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.86%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, which allows remote attackers to gain read-write access via a hard-coded cable-docsis community string and read or modify arbitrary SNMP variables.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.86% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- cisco/ios
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21974Patch, Vendor Advisory
- http://securitytracker.com/id?1016899
- http://www.cisco.com/warp/public/707/cisco-sa-20060920-docsis.shtmlPatch
- http://www.kb.cert.org/vuls/id/123140US Government Resource
- http://www.osvdb.org/29034
- http://www.securityfocus.com/bid/20125Patch
- http://www.vupen.com/english/advisories/2006/3722
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29054
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5665
- http://secunia.com/advisories/21974Patch, Vendor Advisory
- http://securitytracker.com/id?1016899
- http://www.cisco.com/warp/public/707/cisco-sa-20060920-docsis.shtmlPatch
- http://www.kb.cert.org/vuls/id/123140US Government Resource
- http://www.osvdb.org/29034
- http://www.securityfocus.com/bid/20125Patch
- http://www.vupen.com/english/advisories/2006/3722
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29054
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5665
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.