CVE-2007-4786
published 2007-09-10CVE-2007-4786: Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled…
PriorityP419medium5.3CVSS 3.1
AVAACHPRNUINSUCHINAN
EPSS
0.50%
39.3th percentile
Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled, composes %ASA-5-111008 messages from the "test aaa" command with cleartext passwords and sends them over the network to a remote syslog server or places them in a local logging buffer, which allows context-dependent attackers to obtain sensitive information.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | >= 7.0 < 7.0.7.1 | 7.0.7.1 |
| cisco | adaptive_security_appliance_software | >= 7.1 < 7.1.2.61 | 7.1.2.61 |
| cisco | adaptive_security_appliance_software | >= 7.2 < 7.2.2.34 | 7.2.2.34 |
| cisco | adaptive_security_appliance_software | >= 8.0 < 8.0.2.11 | 8.0.2.11 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:A/AC:H/Au:S/C:C/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Missing Encryption of Sensitive Data
mitre_cwe
CWE-311 Missing Encryption of Sensitive Data
CWE-311: Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
Modes of Introduction:
Phase: Architecture and Design
Note: OMISSION: This weakness is caused by missing a security tactic during the architecture and design phase.
Phase: Operation
Common Consequences:
Scope: Confidentiality. Impact: Read Application Data. If the application does not use a secure channel, such as SSL, to exchange sensitive information, it is possible for an attacker with access to the network traffic to sniff packets from the connection and uncover the data. This attack is not technically difficult, but does require physical access to some portion of the network over which the sensitive data travels. This access is usually somewhe
CWE
Cleartext Transmission of Sensitive Information
mitre_cwe
CWE-319 Cleartext Transmission of Sensitive Information
CWE-319: Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Modes of Introduction:
Phase: Architecture and Design
Note: OMISSION: This weakness is caused by missing a security tactic during the architecture and design phase.
Phase: Architecture and Design
Note: For hardware, this may be introduced when design does not plan for an attacker having physical access while a legitimate user is remotely operating the device.
Phase: Operation
Phase: System Configuration
Common Consequences:
Scope: Integrity, Confidentiality. Impact: Read Application Data, Modify Files or Directories. Anyone can read the information by gaining access to the channel being used
http://osvdb.org/37499http://secunia.com/advisories/26677http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsj72903http://www.kb.cert.org/vuls/id/563673http://www.kb.cert.org/vuls/id/MIMG-74ZK93http://www.securityfocus.com/bid/25548http://www.securitytracker.com/id?1018660http://www.vupen.com/english/advisories/2007/3076https://exchange.xforce.ibmcloud.com/vulnerabilities/36473http://osvdb.org/37499http://secunia.com/advisories/26677http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsj72903http://www.kb.cert.org/vuls/id/563673http://www.kb.cert.org/vuls/id/MIMG-74ZK93http://www.securityfocus.com/bid/25548http://www.securitytracker.com/id?1018660http://www.vupen.com/english/advisories/2007/3076https://exchange.xforce.ibmcloud.com/vulnerabilities/36473
2007-09-10
Published