← Back to CVEs
CVE-2006-4991
N/ADescription
RSA Keon Certificate Authority (KeonCA) Manager 6.5.1 and 6.6 allows privileged local users to hide malicious Certificate Authority (CA) activities by modifying CA auditor logs without detection by (1) modifying or deleting a <LOG BLOCK> and its signature from the XML log in a way that is not detected by the integrity check function that operates on the entire pool, or (2) modifying entries in the live log file, which is only signed during rotation.
CVE Details
CVSS v3.1 ScoreN/A
Published9/26/2006
Last Modified4/16/2026
Sourcenvd
Honeypot Sightings0
Affected Products
rsa:keon_certificate_authority_manager
References
http://www.securityfocus.com/archive/1/446742/100/0/threaded(cve@mitre.org)
http://www.securityfocus.com/bid/20136(cve@mitre.org)
https://exchange.xforce.ibmcloud.com/vulnerabilities/29065(cve@mitre.org)
https://exchange.xforce.ibmcloud.com/vulnerabilities/29068(cve@mitre.org)
http://lists.grok.org.uk/pipermail/full-disclosure/2006-September/049592.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/archive/1/446742/100/0/threaded(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/20136(af854a3a-2127-422b-91ae-364da2661108)
https://exchange.xforce.ibmcloud.com/vulnerabilities/29065(af854a3a-2127-422b-91ae-364da2661108)
https://exchange.xforce.ibmcloud.com/vulnerabilities/29068(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.