CVE-2006-4991
Estado: ModificadaBaja (3.6)—
RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 and 6.6 allows privileged local users to hide malicious Certificate Authority (CA) activities by modifying CA auditor logs without detection by (1) modifying or deleting a <LOG BLOCK> and its signature from the XML log in a way that is not detected by the integrity check function that operates on the entire pool, or (2) modifying entries in the live log file, which is only signed during rotation.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N
- Puntuación base: 3.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049592.html
- http://www.securityfocus.com/archive/1/446742/100/0/threaded
- http://www.securityfocus.com/bid/20136
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29065
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29068
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049592.html
- http://www.securityfocus.com/archive/1/446742/100/0/threaded
- http://www.securityfocus.com/bid/20136
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29065
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29068
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-4991",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-09-26T02:07:00.000",
"references": [
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049592.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/446742/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20136",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29065",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29068",
"source": "cve@mitre.org"
},
{
"url": "http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049592.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/446742/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/20136",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29065",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29068",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 and 6.6 allows privileged local users to hide malicious Certificate Authority (CA) activities by modifying CA auditor logs without detection by (1) modifying or deleting a <LOG BLOCK> and its signature from the XML log in a way that is not detected by the integrity check function that operates on the entire pool, or (2) modifying entries in the live log file, which is only signed during rotation."
},
{
"lang": "es",
"value": "RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 y 6.6 permite que los usuarios locales privilegiados ocultar actividades malévolas del Certificate Authority (CA) modificando los registros del interventor del CA sin su detección por (1) modificación o supresión de <LOG BLOCK> y su firma del registro XML abre una sesión de manera que no sea detectada por la función de chequeo de integridad que funciona sobre toda el fondo, o (2) entradas de modificación en el fichero de registro directo, que se firma solamente durante la rotación."
}
],
"lastModified": "2026-06-16T22:30:16.133",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rsa:keon_certificate_authority_manager:6.5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ADDB62CF-F83E-4B57-AE5A-210D46E5FFE1"
},
{
"criteria": "cpe:2.3:a:rsa:keon_certificate_authority_manager:6.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "822111CD-A016-4749-9FB8-25A534D12FCE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}