PT-2007-2395 · Cisco · Cisco Pix 500 Series Security Appliances+2

Published

2007-02-14

·

Updated

2018-10-30

·

CVE-2007-0960

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cisco PIX 500 and ASA 5500 Series Security Appliances version 7.2.2
Description: The issue allows remote authenticated users to gain elevated privileges on the device via unspecified vectors when configured to use the LOCAL authentication method. This could enable an authenticated, remote attacker to gain elevated privileges.
Recommendations: For version 7.2.2, consider disabling the LOCAL authentication method as a temporary workaround until a patch is available. Restrict access to the device to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0960

Affected Products

Cisco Asa 5500 Series Security Appliances
Cisco Asa
Cisco Pix 500 Series Security Appliances