PT-2008-2838 · Cisco · Cisco Pix/Asa Finesse Operation System

Hacka Man

·

Published

2008-03-10

·

Updated

2025-01-17

·

CVE-2008-1246

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco PIX/ASA Finesse Operation System versions 7.1 through 7.2
Description The issue allows local users to gain privileges by entering characters at the enable prompt, erasing these characters via the Backspace key, and then holding down the Backspace key for one second after erasing the final character. It is noted that third parties, including one who works for the vendor, have been unable to reproduce the flaw unless the enable password is blank.
Recommendations For versions 7.1 and 7.2, consider setting a non-blank enable password to minimize the risk of exploitation. As a temporary workaround, restrict local access to the system until a fix is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2008-1246

Affected Products

Cisco Pix/Asa Finesse Operation System