The NeoScale Systems CryptoStor 700 series appliance before 2.6 relies on client-side ActiveX code for smartcard authentication, which allows remote attackers to bypass smartcard authentication, and gain access if able to present a valid username and password, by disabling ActiveX.
References
Link | Resource |
---|---|
http://secunia.com/advisories/23430 | Patch Vendor Advisory |
http://securitytracker.com/id?1017396 | |
http://www.kb.cert.org/vuls/id/339004 | Patch US Government Resource |
http://www.securityfocus.com/bid/21652 | |
http://www.vupen.com/english/advisories/2006/5063 | |
http://secunia.com/advisories/23430 | Patch Vendor Advisory |
http://securitytracker.com/id?1017396 | |
http://www.kb.cert.org/vuls/id/339004 | Patch US Government Resource |
http://www.securityfocus.com/bid/21652 | |
http://www.vupen.com/english/advisories/2006/5063 |
Configurations
History
21 Nov 2024, 00:14
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/23430 - Patch, Vendor Advisory | |
References | () http://securitytracker.com/id?1017396 - | |
References | () http://www.kb.cert.org/vuls/id/339004 - Patch, US Government Resource | |
References | () http://www.securityfocus.com/bid/21652 - | |
References | () http://www.vupen.com/english/advisories/2006/5063 - |
Information
Published : 2006-12-19 19:28
Updated : 2025-04-09 00:30
NVD link : CVE-2006-3896
Mitre link : CVE-2006-3896
CVE.ORG link : CVE-2006-3896
JSON object : View
Products Affected
neoscale_systems
- cryptostor_tape_700
CWE