cbcvebase.
CVE-2007-4786
published 2007-09-10

CVE-2007-4786: Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled…

PriorityP419medium5.3CVSS 3.1
AVAACHPRNUINSUCHINAN
EPSS
0.50%
39.3th percentile
Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled, composes %ASA-5-111008 messages from the "test aaa" command with cleartext passwords and sends them over the network to a remote syslog server or places them in a local logging buffer, which allows context-dependent attackers to obtain sensitive information.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance_software>= 7.0 < 7.0.7.17.0.7.1
ciscoadaptive_security_appliance_software>= 7.1 < 7.1.2.617.1.2.61
ciscoadaptive_security_appliance_software>= 7.2 < 7.2.2.347.2.2.34
ciscoadaptive_security_appliance_software>= 8.0 < 8.0.2.118.0.2.11

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:A/AC:H/Au:S/C:C/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.