CVE-2006-3291

Cisco IOS 12.3(8)JA-12.3(8)JA1 - RCE

Title source: llm
STIX 2.1

Description

The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the "Local User List Only (Individual Passwords)" setting, which removes all security and password configurations and allows remote attackers to access the system.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18704
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27437
Patch vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20060628-ap.shtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/26878
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016399
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2584
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/544484
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20860

Scores

EPSS 0.0374
EPSS Percentile 88.7%

Details

CWE
CWE-16
Status published
Products (2)
cisco/ios 12.3\(8\)ja
cisco/ios 12.3\(8\)ja1
Published Jun 28, 2006
Tracked Since Feb 18, 2026