PT-2008-2838 · Cisco · Cisco Pix/Asa Finesse Operation System
Hacka Man
·
Published
2008-03-10
·
Updated
2025-01-17
·
CVE-2008-1246
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco PIX/ASA Finesse Operation System versions 7.1 through 7.2
Description
The issue allows local users to gain privileges by entering characters at the enable prompt, erasing these characters via the Backspace key, and then holding down the Backspace key for one second after erasing the final character. It is noted that third parties, including one who works for the vendor, have been unable to reproduce the flaw unless the enable password is blank.
Recommendations
For versions 7.1 and 7.2, consider setting a non-blank enable password to minimize the risk of exploitation.
As a temporary workaround, restrict local access to the system until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Pix/Asa Finesse Operation System