Vulnerability Description
Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user passwords, and the enable password to be changed to a "non-random value" under certain circumstances, which causes administrators to be locked out and might allow attackers to gain access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Pix Firewall 501 | All versions |
| Cisco | Pix Firewall 506 | All versions |
| Cisco | Pix Firewall 515 | All versions |
| Cisco | Pix Firewall 515E | All versions |
| Cisco | Pix Firewall 520 | All versions |
| Cisco | Pix Firewall 525 | All versions |
| Cisco | Pix Firewall 535 | All versions |
| Cisco | Pix Firewall Software | 6.3 |
| Cisco | Adaptive Security Appliance | All versions |
References
- http://secunia.com/advisories/21616
- http://securitytracker.com/id?1016738
- http://securitytracker.com/id?1016739
- http://securitytracker.com/id?1016740
- http://www.cisco.com/warp/public/707/cisco-sa-20060823-firewall.shtmlVendor Advisory
- http://www.osvdb.org/28143
- http://www.securityfocus.com/bid/19681
- http://www.vupen.com/english/advisories/2006/3367
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28540
- http://secunia.com/advisories/21616
- http://securitytracker.com/id?1016738
- http://securitytracker.com/id?1016739
- http://securitytracker.com/id?1016740
- http://www.cisco.com/warp/public/707/cisco-sa-20060823-firewall.shtmlVendor Advisory
- http://www.osvdb.org/28143
FAQ
What is CVE-2006-4312?
CVE-2006-4312 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to ...
How severe is CVE-2006-4312?
CVE-2006-4312 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4312?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Pix Firewall 501, Cisco Pix Firewall 506, Cisco Pix Firewall 515, Cisco Pix Firewall 515E, Cisco Pix Firewall 520.