CVE-2007-0058
Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
- EPSS
- 2.62% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- cisco/network admission control manager and server system software
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/23556Third Party Advisory
- http://securitytracker.com/id?1017465Third Party Advisory, VDB Entry
- http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtmlVendor Advisory
- http://www.osvdb.org/32579Broken Link
- http://www.vupen.com/english/advisories/2007/0030Third Party Advisory
- http://secunia.com/advisories/23556Third Party Advisory
- http://securitytracker.com/id?1017465Third Party Advisory, VDB Entry
- http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtmlVendor Advisory
- http://www.osvdb.org/32579Broken Link
- http://www.vupen.com/english/advisories/2007/0030Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.