CVE-2006-4950

Cisco IOS 12.2-12.4 - Unauthenticated SNMP Variable Read/Write via Hard-Coded Community String

Title source: llm
STIX 2.1

Description

Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, which allows remote attackers to gain read-write access via a hard-coded cable-docsis community string and read or modify arbitrary SNMP variables.

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016899
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3722
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5665
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/123140
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29054
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21974
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/29034
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20125

Scores

EPSS 0.0567
EPSS Percentile 92.2%

Details

Status published
Products (50)
cisco/ios 12.3\(1a\)
cisco/ios 12.3\(2\)ja
cisco/ios 12.3\(2\)ja5
cisco/ios 12.3\(2\)jk
cisco/ios 12.3\(2\)jk1
cisco/ios 12.3\(2\)t3
cisco/ios 12.3\(2\)t8
cisco/ios 12.3\(2\)xa4
cisco/ios 12.3\(2\)xa5
cisco/ios 12.3\(2\)xc1
... and 40 more
Published Sep 23, 2006
Tracked Since Feb 18, 2026