CVE-2005-4332

critical Cisco
CVSS v3 Base Score
9.4
AV:N/AC:L/Au:N/C:N/I:C/A:C
EPSS Score
11.1%
Exploitation probability in 30 days
Top 7% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
None
Integrity
C
Availability
C
Published: December 17, 2005 (7453 days ago)
Last Modified: April 16, 2026
Vendor: Cisco
Source: NVD

Description

Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service or upload files via direct requests to obsolete JSP files including (1) admin/uploadclient.jsp, (2) apply_firmware_action.jsp, and (3) file.jsp.

CWE

NVD-CWE-Other

Affected Products

cisco network admission control manager and server system software

References