Cisco Security Agent Management Center (CSAMC) 5.1 before 5.1.0.79 does not properly handle certain LDAP error messages, which allows remote attackers to bypass authentication requirements via an empty password when using an external LDAP server.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/29955 | vdb entry |
http://secunia.com/advisories/22684 | third party advisory |
http://www.cisco.com/en/US/products/products_security_advisory09186a00807726f7.shtml | patch vendor advisory |
http://www.osvdb.org/30169 | vdb entry |
http://www.vupen.com/english/advisories/2006/4308 | vdb entry |
http://www.securityfocus.com/bid/20852 | patch vdb entry |
http://securitytracker.com/id?1017148 | vdb entry |
http://www.kb.cert.org/vuls/id/778648 | third party advisory us government resource |