// For flags

CVE-2006-4991

 

Severity Score

5.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 and 6.6 allows privileged local users to hide malicious Certificate Authority (CA) activities by modifying CA auditor logs without detection by (1) modifying or deleting a <LOG BLOCK> and its signature from the XML log in a way that is not detected by the integrity check function that operates on the entire pool, or (2) modifying entries in the live log file, which is only signed during rotation.

RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 y 6.6 permite que los usuarios locales privilegiados ocultar actividades malévolas del Certificate Authority (CA) modificando los registros del interventor del CA sin su detección por (1) modificación o supresión de <LOG BLOCK> y su firma del registro XML abre una sesión de manera que no sea detectada por la función de chequeo de integridad que funciona sobre toda el fondo, o (2) entradas de modificación en el fichero de registro directo, que se firma solamente durante la rotación.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-09-25 CVE Reserved
  • 2006-09-26 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Rsa
Search vendor "Rsa"
Keon Certificate Authority Manager
Search vendor "Rsa" for product "Keon Certificate Authority Manager"
6.5.1
Search vendor "Rsa" for product "Keon Certificate Authority Manager" and version "6.5.1"
-
Affected
Rsa
Search vendor "Rsa"
Keon Certificate Authority Manager
Search vendor "Rsa" for product "Keon Certificate Authority Manager"
6.6
Search vendor "Rsa" for product "Keon Certificate Authority Manager" and version "6.6"
-
Affected