CVE-2006-3291: Critical severity Cisco IOS vulnerability
The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the "Local User List Only (Individual Passwords)" setting, which removes all security and password configurations and allows remote attackers to access the system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3291?
CVE-2006-3291 is classified as a medium severity vulnerability due to its potential to compromise device security settings.
How do I fix CVE-2006-3291?
To fix CVE-2006-3291, ensure that you do not configure the web interface to use the 'Local User List Only (Individual Passwords)' option.
What devices are affected by CVE-2006-3291?
CVE-2006-3291 affects Cisco Wireless Access Points and Wireless Bridges running IOS version 12.3(8)JA and 12.3(8)JA1.
What does CVE-2006-3291 allow an attacker to do?
CVE-2006-3291 allows an attacker to gain unauthorized access by bypassing security configurations.
Is there a workaround for CVE-2006-3291?
The best workaround for CVE-2006-3291 is to avoid using the 'Local User List Only (Individual Passwords)' setting in the web interface.