MEDIUM · 4.6

CVE-2006-4982

Cisco NAC maintains an exception list that does not record device properties other than MAC address, which allows physically proximate attackers to bypass control methods and join a local network by s...

Vulnerability Description

Cisco NAC maintains an exception list that does not record device properties other than MAC address, which allows physically proximate attackers to bypass control methods and join a local network by spoofing the MAC address of a different type of device, as demonstrated by using the MAC address of a disconnected printer.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CiscoNetwork Access ControlAll versions

References

FAQ

What is CVE-2006-4982?

CVE-2006-4982 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Cisco NAC maintains an exception list that does not record device properties other than MAC address, which allows physically proximate attackers to bypass control methods and join a local network by s...

How severe is CVE-2006-4982?

CVE-2006-4982 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-4982?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Network Access Control.