CVE

CVE-2007-0058

Severity:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
04/01/2007
Last modified:
30/10/2018

Description

Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:network_admission_control_manager_and_server_system_software:*:*:*:*:*:*:*:* 3.5.0 (including) 3.5.9 (including)
cpe:2.3:a:cisco:network_admission_control_manager_and_server_system_software:*:*:*:*:*:*:*:* 3.6.0.0 (including) 3.6.1.1 (including)