Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://secunia.com/advisories/23617 | third party advisory |
http://www.vupen.com/english/advisories/2007/0030 | vdb entry third party advisory |
http://osvdb.org/32578 | vdb entry broken link |
http://www.cisco.com/warp/public/707/cisco-sa-20070103-CleanAccess.shtml | patch vendor advisory |
http://securitytracker.com/id?1017465 | vdb entry third party advisory |