PT-2007-2395 · Cisco · Cisco Pix 500 Series Security Appliances+2
Published
2007-02-14
·
Updated
2018-10-30
·
CVE-2007-0960
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Cisco PIX 500 and ASA 5500 Series Security Appliances version 7.2.2
Description:
The issue allows remote authenticated users to gain elevated privileges on the device via unspecified vectors when configured to use the LOCAL authentication method. This could enable an authenticated, remote attacker to gain elevated privileges.
Recommendations:
For version 7.2.2, consider disabling the LOCAL authentication method as a temporary workaround until a patch is available. Restrict access to the device to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Asa 5500 Series Security Appliances
Cisco Asa
Cisco Pix 500 Series Security Appliances