Cisco Clean Access (CCA) 3.5.x up to and including 3.5.9 and 3.6.x up to and including 3.6.1.1 on the Clean Access Manager (CAM) allows remote malicious users to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cisco network admission control manager and server system software |