Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-4786
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-4786

Description:
Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled, composes %ASA-5-111008 messages from the "test aaa" command with cleartext passwords and sends them over the network to a remote syslog server or places them in a local logging buffer, which allows context-dependent attackers to obtain sensitive information.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/36473

ST
  1018660

SAID
  Secunia Advisory: SA26677

OSVDB
  37499

MISC
  http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsj72903

CONFIRM
  http://www.kb.cert.org/vuls/id/MIMG-74ZK93

CERT-VN
  563673

BID
  25548


Return to the previous page.