7.5

CVE-2005-4499

The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the username from the cleartext portion of a RADIUS session, then using the password to log in to another device that uses CS ACS.

Data is provided by the National Vulnerability Database (NVD)
CiscoVpn 3030 Concentator Version4.7.1
CiscoVpn 3030 Concentator Version4.7.1.f
CiscoPix Firewall Version6.2.2_.111
CiscoSecure Access Control Server Version2.0 Editionunix
CiscoSecure Access Control Server Version2.1 Editionwindows_nt
CiscoSecure Access Control Server Version2.3 Editionunix
CiscoSecure Access Control Server Version2.3 Editionwindows_nt
CiscoSecure Access Control Server Version2.3.5.1 Editionunix
CiscoSecure Access Control Server Version2.3.6.1 Editionunix
CiscoSecure Access Control Server Version2.4 Editionwindows_nt
CiscoSecure Access Control Server Version2.5 Editionwindows_nt
CiscoSecure Access Control Server Version2.6 Editionwindows_nt
CiscoSecure Access Control Server Version2.6.2 Editionwindows_nt
CiscoSecure Access Control Server Version2.6.3 Editionwindows_nt
CiscoSecure Access Control Server Version2.6.4 Editionwindows_nt
CiscoSecure Access Control Server Version2.42 Editionwindows_nt
CiscoSecure Access Control Server Version3.0 Editionwindows_nt
CiscoSecure Access Control Server Version3.0.1 Editionwindows_nt
CiscoSecure Access Control Server Version3.0.3 Editionwindows_nt
CiscoSecure Access Control Server Version3.1.1 Editionwindows_nt
CiscoSecure Access Control Server Version3.2 Editionwindows_server
CiscoPix Firewall Software Version2.7
CiscoPix Firewall Software Version3.0
CiscoPix Firewall Software Version3.1
CiscoPix Firewall Software Version4.0
CiscoPix Firewall Software Version4.2
CiscoPix Firewall Software Version4.3
CiscoPix Firewall Software Version4.4
CiscoPix Firewall Software Version5.0
CiscoPix Firewall Software Version5.1
CiscoPix Firewall Software Version5.2
CiscoPix Firewall Software Version5.3
CiscoPix Firewall Software Version6.0
CiscoPix Firewall Software Version6.1
CiscoPix Firewall Software Version6.2
CiscoPix Firewall Software Version6.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.91% 0.825
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P