Lucene search

K
ciscoCiscoCISCO-SA-20070214-CVE-2007-0960
HistoryFeb 14, 2007 - 11:06 p.m.

Cisco PIX and ASA LOCAL Method Privilege Escalation Vulnerability

2007-02-1423:06:59
tools.cisco.com
13

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS

0.005

Percentile

75.8%

Cisco PIX 500 Series Security Appliances and Cisco ASA 5500 Series Adaptive Security Appliances (ASA) contain a vulnerability that could allow an authenticated, remote attacker to gain elevated privileges on the device.

The vulnerability only exists on devices using LOCAL method for user authentication. The attacker must also be defined in the local database with a privilege of zero and be able to authenticate to the device. If these conditions are met, an attacker could grant themselves administrative privileges.

The vendor has given this issue a CVSS score to reflect the availability of functional exploit code; however, the code is not known to be publicly available.

Cisco has confirmed this vulnerability and updated software is available.

In order to exploit this vulnerability, an attacker must be defined in the local database with a privilege level of zero and be able to authenticate to the affected device. These conditions greatly reduce the likelihood of attacks, as only trusted users should be defined in the local database. It should also be noted that the affected devices are not vulnerable in their default configurations.

Affected configurations

Vulners
Node
ciscopix_asa_idsMatchany
OR
ciscopix_asa_idsMatchany
VendorProductVersionCPE
ciscopix_asa_idsanycpe:2.3:a:cisco:pix_asa_ids:any:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS

0.005

Percentile

75.8%

Related for CISCO-SA-20070214-CVE-2007-0960