CVE-2006-4950: Critical severity Cisco IOS vulnerability
Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, which allows remote attackers to gain read-write access via a hard-coded cable-docsis community string and read or modify arbitrary SNMP variables.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4950?
CVE-2006-4950 is rated as high severity due to its potential to allow remote attackers to gain unauthorized access to sensitive information.
How do I fix CVE-2006-4950?
To fix CVE-2006-4950, update your Cisco IOS software to a version that addresses this vulnerability, specifically one released after September 20, 2006.
Which Cisco devices are affected by CVE-2006-4950?
CVE-2006-4950 affects Cisco IOS versions 12.2 through 12.4 on devices like Cisco IAD2430, VG224 Analog Phone Gateway, and Mobile Wireless Edge Routers.
Can CVE-2006-4950 be exploited remotely?
Yes, CVE-2006-4950 can be exploited remotely, allowing attackers to read sensitive data without authentication.
What are the potential consequences of CVE-2006-4950 exploitation?
Exploitation of CVE-2006-4950 could lead to exposure of sensitive configuration and management information, impacting the integrity and confidentiality of network operations.