Description
The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the "Local User List Only (Individual Passwords)" setting, which removes all security and password configurations and allows remote attackers to access the system.
References (8)
Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/18704
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27437
Patch vendor-advisory
x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20060628-ap.shtml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/26878
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1016399
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2584
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/544484
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/20860
Scores
EPSS
0.0374
EPSS Percentile
88.7%
Details
CWE
CWE-16
Status
published
Products (2)
cisco/ios
12.3\(8\)ja
cisco/ios
12.3\(8\)ja1
Published
Jun 28, 2006
Tracked Since
Feb 18, 2026