Lucene search

K
cveMitreCVE-2006-2322
HistoryMay 12, 2006 - 12:02 a.m.

CVE-2006-2322

2006-05-1200:02:00
mitre
web.nvd.nist.gov
26
cisco
avs
transparent proxy
remote code execution
vulnerability
cve-2006-2322
nvd
bug id
cscsd32143

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.8

Confidence

High

EPSS

0.018

Percentile

88.4%

The transparent proxy feature of the Cisco Application Velocity System (AVS) 3110 5.0 and 4.0 and earlier, and 3120 5.0.0 and earlier, has a default configuration that allows remote attackers to proxy arbitrary TCP connections, aka Bug ID CSCsd32143.

Affected configurations

Nvd
Node
ciscoapplication_velocity_system_3110Match4.0
OR
ciscoapplication_velocity_system_3110Match5.0
OR
ciscoapplication_velocity_system_3120Match5.0
VendorProductVersionCPE
ciscoapplication_velocity_system_31104.0cpe:2.3:h:cisco:application_velocity_system_3110:4.0:*:*:*:*:*:*:*
ciscoapplication_velocity_system_31105.0cpe:2.3:h:cisco:application_velocity_system_3110:5.0:*:*:*:*:*:*:*
ciscoapplication_velocity_system_31205.0cpe:2.3:h:cisco:application_velocity_system_3120:5.0:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.8

Confidence

High

EPSS

0.018

Percentile

88.4%

Related for CVE-2006-2322