7.5
CVSSv2

CVE-2005-2631

Published: 23/08/2005 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cisco Clean Access (CCA) 3.3.0 to 3.3.9, 3.4.0 to 3.4.5, and 3.5.0 to 3.5.3 does not properly authenticate users when invoking API methods, which could allow remote malicious users to bypass security checks, change the assigned role of a user, or disconnect users.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco network admission control manager and server system software 3.3.3

cisco network admission control manager and server system software 3.3.4

cisco network admission control manager and server system software 3.4.1

cisco network admission control manager and server system software 3.4.2

cisco network admission control manager and server system software 3.4.3

cisco network admission control manager and server system software 3.3

cisco network admission control manager and server system software 3.3.7

cisco network admission control manager and server system software 3.3.8

cisco network admission control manager and server system software 3.5

cisco network admission control manager and server system software 3.5.1

cisco network admission control manager and server system software 3.3.5

cisco network admission control manager and server system software 3.3.6

cisco network admission control manager and server system software 3.4.4

cisco network admission control manager and server system software 3.4.5

cisco network admission control manager and server system software 3.3.1

cisco network admission control manager and server system software 3.3.2

cisco network admission control manager and server system software 3.3.9

cisco network admission control manager and server system software 3.4

cisco network admission control manager and server system software 3.5.2

cisco network admission control manager and server system software 3.5.3

Vendor Advisories

Cisco Clean Access (CCA) is a software solution that can automatically detect, isolate, and clean infected or vulnerable devices that attempt to access your network CCA includes as part of the architecture an Application Program Interface (API) Lack of authentication while invoking API methods can allow an attacker to bypass security p ...