CVE-2007-0960
published 2007-02-16CVE-2007-0960: Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote…
PriorityP338critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
2.56%
83.3th percentile
Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asa_5500 | — | — |
| cisco | pix_firewall_software | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco PIX and ASA LOCAL Method Privilege Escalation Vulnerability
vendor_cisco·2007-02-14·CVSS 9.0
CVE-2007-0960 [CRITICAL] CWE-264 Cisco PIX and ASA LOCAL Method Privilege Escalation Vulnerability
Cisco PIX and ASA LOCAL Method Privilege Escalation Vulnerability
Cisco PIX 500 Series Security Appliances and Cisco ASA 5500 Series Adaptive Security Appliances (ASA) contain a vulnerability that could allow an authenticated, remote attacker to gain elevated privileges on the device.
The vulnerability only exists on devices using LOCAL method for user authentication. The attacker must also be defined in the local database with a privilege of zero and be able to authenticate to the device. If these conditions are met, an attacker could grant themselves administrative privileges.
The vendor has given this issue a CVSS score to reflect the availability of functional exploit code; however, the code is not known to be publicly available.
Cisco has confirmed this vulnerability and updated soft
GHSA
GHSA-8cxh-mfqx-j4v2: Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7
ghsa_unreviewed·2022-05-01
CVE-2007-0960 [HIGH] GHSA-8cxh-mfqx-j4v2: Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7
Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/33063http://secunia.com/advisories/24160http://secunia.com/advisories/24179http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtmlhttp://www.securityfocus.com/bid/22561http://www.securityfocus.com/bid/22562http://www.securitytracker.com/id?1017651http://www.securitytracker.com/id?1017652http://www.vupen.com/english/advisories/2007/0608https://exchange.xforce.ibmcloud.com/vulnerabilities/32489http://osvdb.org/33063http://secunia.com/advisories/24160http://secunia.com/advisories/24179http://www.cisco.com/en/US/products/products_security_advisory09186a00807e2484.shtmlhttp://www.securityfocus.com/bid/22561http://www.securityfocus.com/bid/22562http://www.securitytracker.com/id?1017651http://www.securitytracker.com/id?1017652http://www.vupen.com/english/advisories/2007/0608https://exchange.xforce.ibmcloud.com/vulnerabilities/32489
2007-02-16
Published