Password Disclosure Vulnerability in Cisco Secure Access Control Server
CVE-2006-0561

Currently unrated

Key Information:

Vendor

Cisco

Vendor
CVE Published:
10 May 2006

What is CVE-2006-0561?

The Cisco Secure Access Control Server (ACS) 3.x for Windows suffers from a vulnerability that permits storage of administrator passwords and master keys in the registry with inadequate permissions. This security flaw enables local users and potential remote administrators to exploit the system. By utilizing Microsoft's cryptographic API functions, they can decrypt these credentials and obtain the plaintext version of the sensitive master key, resulting in unauthorized access to administrative capabilities.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2006-0561 : Password Disclosure Vulnerability in Cisco Secure Access Control Server