← Back

CVE-2006-4312

nvd nist
Published: Aug 23, 2006Modified: Apr 16, 2026

JSON object

Loading...
6.8
Vector
AV:L/AC:L/Au:S/C:C/I:C/A:C
Exploitability: 3.1 / Impact: 10.0
Source: NVD

Description

Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user passwords, and the enable password to be changed to a "non-random value" under certain circumstances, which causes administrators to be locked out and might allow attackers to gain access.

Affected (9)

9 products
Pix Firewall 501
Pix Firewall 506
Pix Firewall 515
Pix Firewall 515e
Pix Firewall 520
Pix Firewall 525
Pix Firewall 535
Pix Firewall Software
Adaptive Security Appliance
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
Version 6.3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (18)

Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.