First published: Wed Jun 28 2006(Updated: )
The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the "Local User List Only (Individual Passwords)" setting, which removes all security and password configurations and allows remote attackers to access the system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =12.3\(8\)ja1 | |
Cisco IOS | =12.3\(8\)ja |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3291 is classified as a medium severity vulnerability due to its potential to compromise device security settings.
To fix CVE-2006-3291, ensure that you do not configure the web interface to use the 'Local User List Only (Individual Passwords)' option.
CVE-2006-3291 affects Cisco Wireless Access Points and Wireless Bridges running IOS version 12.3(8)JA and 12.3(8)JA1.
CVE-2006-3291 allows an attacker to gain unauthorized access by bypassing security configurations.
The best workaround for CVE-2006-3291 is to avoid using the 'Local User List Only (Individual Passwords)' setting in the web interface.