CVE-2006-0485

UnknownEPSS 0.35%

Last modified

CVE-2006-0485 is a vulnerability of currently unknown severity. The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh73049.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.

Description

The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh73049.

Metrics

EPSS Probability
0.35%

26.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CiscoIos12.0t
CiscoIos12.0xh
CiscoIos12.0xk
CiscoIos12.0xl
CiscoIos12.0xn
CiscoIos12.0xr
CiscoIos12.1
CiscoIos12.1aa
CiscoIos12.1e
CiscoIos12.1ec
CiscoIos12.1ez
CiscoIos12.1ga
CiscoIos12.1gb
CiscoIos12.1t
CiscoIos12.1xa
CiscoIos12.1xe
CiscoIos12.1xh
CiscoIos12.1xi
CiscoIos12.1xj
CiscoIos12.1xl
CiscoIos12.1xm
CiscoIos12.1xp
CiscoIos12.1xq
CiscoIos12.1xs
CiscoIos12.1xt
CiscoIos12.1xu
CiscoIos12.1xv
CiscoIos12.1xw
CiscoIos12.1xy
CiscoIos12.1xz
CiscoIos12.1ya
CiscoIos12.1yb
CiscoIos12.1yd
CiscoIos12.1ye
CiscoIos12.1yf
CiscoIos12.1yh
CiscoIos12.1yi
CiscoIos12.2
CiscoIos12.2b
CiscoIos12.2bw
CiscoIos12.2by
CiscoIos12.2dd
CiscoIos12.2dx
CiscoIos12.2mx
CiscoIos12.2n
CiscoIos12.2s
CiscoIos12.2su
CiscoIos12.2sw
CiscoIos12.2sxb
CiscoIos12.2sxd

Showing 50 of 130 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-0485?
The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh73049.
How severe is CVE-2006-0485?
Severity scoring for CVE-2006-0485 is pending analysis. The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2006-0485?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-0485?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST