CVE-2006-4991
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 and 6.6 allows privileged local users to hide malicious Certificate Authority (CA) activities by modifying CA auditor logs without detection by (1) modifying or deleting a <LOG BLOCK> and its signature from the XML log in a way that is not detected by the integrity check function that operates on the entire pool, or (2) modifying entries in the live log file, which is only signed during rotation.
RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 y 6.6 permite que los usuarios locales privilegiados ocultar actividades malévolas del Certificate Authority (CA) modificando los registros del interventor del CA sin su detección por (1) modificación o supresión de <LOG BLOCK> y su firma del registro XML abre una sesión de manera que no sea detectada por la función de chequeo de integridad que funciona sobre toda el fondo, o (2) entradas de modificación en el fichero de registro directo, que se firma solamente durante la rotación.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-09-25 CVE Reserved
- 2006-09-26 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/446742/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/20136 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/29065 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/29068 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049592.html | 2018-10-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rsa Search vendor "Rsa" | Keon Certificate Authority Manager Search vendor "Rsa" for product "Keon Certificate Authority Manager" | 6.5.1 Search vendor "Rsa" for product "Keon Certificate Authority Manager" and version "6.5.1" | - |
Affected
| ||||||
Rsa Search vendor "Rsa" | Keon Certificate Authority Manager Search vendor "Rsa" for product "Keon Certificate Authority Manager" | 6.6 Search vendor "Rsa" for product "Keon Certificate Authority Manager" and version "6.6" | - |
Affected
|