Synced 16 Jun 2026 15:24 UTC Account
← All products

CVE-2006-3291

HIGH severity · CVSS 9.3 · CWE-16
9.3CVSS HIGH

Summary

The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the "Local User List Only (Individual Passwords)" setting, which removes all security and password configurations and allows remote attackers to access the system.

Impact & exploitability

Attack vectorNetwork
Attack complexity
Privileges required
User interaction
Confidentiality impact
Integrity impact
Availability impact
Exploit probability (EPSS)4%

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: http://www.cisco.com/warp/public/707/cisco-sa-20060628-ap.shtml ↗