CVE-2006-4312

UnknownEPSS 0.32%

Last modified

CVE-2006-4312 is a vulnerability of currently unknown severity. Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user passwords, and the enable password to be changed to a "non-random value" under certain circumstances, which causes administrators to be locked out and might allow attackers to gain access.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.

Description

Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user passwords, and the enable password to be changed to a "non-random value" under certain circumstances, which causes administrators to be locked out and might allow attackers to gain access.

Metrics

EPSS Probability
0.32%

23.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CiscoPix Firewall 501All versions
CiscoPix Firewall 506All versions
CiscoPix Firewall 515All versions
CiscoPix Firewall 515eAll versions
CiscoPix Firewall 520All versions
CiscoPix Firewall 525All versions
CiscoPix Firewall 535All versions
CiscoPix Firewall Software6.3
CiscoAdaptive Security ApplianceAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-4312?
Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user passwords, and the enable password to be changed to a "non-random value" under certain circumstances, which causes administrators to be locked out and might allow attackers to gain access.
How severe is CVE-2006-4312?
Severity scoring for CVE-2006-4312 is pending analysis. The EPSS model estimates a 0.32% probability of exploitation in the next 30 days.
How do I fix CVE-2006-4312?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-4312?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST