Lucene search

K
nvd[email protected]NVD:CVE-2009-1155
HistoryApr 09, 2009 - 3:08 p.m.

CVE-2009-1155

2009-04-0915:08:35
CWE-287
web.nvd.nist.gov
4

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.005

Percentile

75.7%

Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2(4)27, 8.0 before 8.0(4)25, and 8.1 before 8.1(2)15, when AAA override-account-disable is entered in a general-attributes field, allow remote attackers to bypass authentication and establish a VPN session to an ASA device via unspecified vectors.

Affected configurations

Nvd
Node
ciscoadaptive_security_appliance_5500Match7.1
OR
ciscoadaptive_security_appliance_5500Match7.2
OR
ciscoadaptive_security_appliance_5500Match8.0
OR
ciscoadaptive_security_appliance_5500Match8.1
OR
ciscopixMatch7.1
OR
ciscopixMatch7.2
OR
ciscopixMatch8.0
OR
ciscopixMatch8.1
VendorProductVersionCPE
ciscoadaptive_security_appliance_55007.1cpe:2.3:h:cisco:adaptive_security_appliance_5500:7.1:*:*:*:*:*:*:*
ciscoadaptive_security_appliance_55007.2cpe:2.3:h:cisco:adaptive_security_appliance_5500:7.2:*:*:*:*:*:*:*
ciscoadaptive_security_appliance_55008.0cpe:2.3:h:cisco:adaptive_security_appliance_5500:8.0:*:*:*:*:*:*:*
ciscoadaptive_security_appliance_55008.1cpe:2.3:h:cisco:adaptive_security_appliance_5500:8.1:*:*:*:*:*:*:*
ciscopix7.1cpe:2.3:h:cisco:pix:7.1:*:*:*:*:*:*:*
ciscopix7.2cpe:2.3:h:cisco:pix:7.2:*:*:*:*:*:*:*
ciscopix8.0cpe:2.3:h:cisco:pix:8.0:*:*:*:*:*:*:*
ciscopix8.1cpe:2.3:h:cisco:pix:8.1:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.005

Percentile

75.7%