CVE-2006-5660
Cisco Security Agent Management Center (CSAMC) 5.1 before 5.1.0.79 does not properly handle certain LDAP error messages, which allows remote attackers to bypass authentication requirements via an empty password when using an external LDAP server.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco Security Agent Management Center (CSAMC) 5.1 before 5.1.0.79 does not properly handle certain LDAP error messages, which allows remote attackers to bypass authentication requirements via an empty password when using an external LDAP server.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 3.68% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- cisco/security agent management center
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/22684
- http://securitytracker.com/id?1017148
- http://www.cisco.com/en/US/products/products_security_advisory09186a00807726f7.shtmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/778648US Government Resource
- http://www.osvdb.org/30169
- http://www.securityfocus.com/bid/20852Patch
- http://www.vupen.com/english/advisories/2006/4308
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29955
- http://secunia.com/advisories/22684
- http://securitytracker.com/id?1017148
- http://www.cisco.com/en/US/products/products_security_advisory09186a00807726f7.shtmlPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/778648US Government Resource
- http://www.osvdb.org/30169
- http://www.securityfocus.com/bid/20852Patch
- http://www.vupen.com/english/advisories/2006/4308
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29955
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.