Vulnerability CVE-2006-3595


Published: 2006-07-18   Modified: 2012-02-12

Description:
The default configuration of IOS HTTP server in Cisco Router Web Setup (CRWS) before 3.3.0 build 31 does not require credentials, which allows remote attackers to access the server with arbitrary privilege levels, aka bug CSCsa78190.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Cisco -> Router web setup 

 References:
http://www.kb.cert.org/vuls/id/205225
http://www.cisco.com/warp/public/707/cisco-sa-20060712-crws.shtml
http://xforce.iss.net/xforce/xfdb/27688
http://www.vupen.com/english/advisories/2006/2773
http://www.securityfocus.com/bid/18953
http://secunia.com/advisories/21028
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5826
http://www.osvdb.org/27159
http://securitytracker.com/id?1016476

Copyright 2024, cxsecurity.com

 

Back to Top