Cisco PIX/ASA Enable Login Prompt Privilege Escalation Vulnerability
BID:27457
Info
Cisco PIX/ASA Enable Login Prompt Privilege Escalation Vulnerability
| Bugtraq ID: | 27457 |
| Class: | Unknown |
| CVE: |
CVE-2008-1246 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 24 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Terry Bunn discovered this issue. |
| Vulnerable: |
Cisco PIX/ASA 7.2.2 Cisco PIX/ASA 7.2.(2.8) Cisco PIX/ASA 7.2.(2.7) Cisco PIX/ASA 7.2.(2.19) Cisco PIX/ASA 7.2.(2.17) Cisco PIX/ASA 7.2.(2.16) Cisco PIX/ASA 7.2(3)006 Cisco PIX/ASA 7.2(2.24) Cisco PIX/ASA 7.2(2.15) Cisco PIX/ASA 7.2(2.14) Cisco PIX/ASA 7.2(2.10) Cisco PIX/ASA 7.2(2) Cisco PIX/ASA 7.2(1.22) Cisco PIX/ASA 7.2(1) Cisco PIX/ASA 7.1.(2.49) Cisco PIX/ASA 7.1.(2.48) Cisco PIX/ASA 7.1(2.5) Cisco PIX/ASA 7.1(2.27) Cisco PIX/ASA 7.1(2) Cisco PIX/ASA 7.1 (2.55) |
| Not Vulnerable: | |
Discussion
Cisco PIX/ASA Enable Login Prompt Privilege Escalation Vulnerability
Cisco PIX and ASA are potentially prone to a privilege-escalation vulnerability.
Exploiting this issue allows authenticated attackers to gain administrative privileges on affected devices. This may facilitate the complete compromise of the affected device.
This issue affects the Cisco PIX/ASA operating system Finesse 7.1 and 7.2. Other versions may also be affected.
This issue may be related to the one documented in BID 22562 (Cisco PIX/ASA Privilege Escalation Vulnerability), but not enough information is currently available to confirm this.
Note that Cisco cannot reproduce this issue at this time.
Cisco PIX and ASA are potentially prone to a privilege-escalation vulnerability.
Exploiting this issue allows authenticated attackers to gain administrative privileges on affected devices. This may facilitate the complete compromise of the affected device.
This issue affects the Cisco PIX/ASA operating system Finesse 7.1 and 7.2. Other versions may also be affected.
This issue may be related to the one documented in BID 22562 (Cisco PIX/ASA Privilege Escalation Vulnerability), but not enough information is currently available to confirm this.
Note that Cisco cannot reproduce this issue at this time.
Exploit / POC
Cisco PIX/ASA Enable Login Prompt Privilege Escalation Vulnerability
To exploit this issue, attackers can use readily available network utilities or direct console access.
To exploit this issue, attackers can use readily available network utilities or direct console access.
Solution / Fix
Cisco PIX/ASA Enable Login Prompt Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco PIX/ASA Enable Login Prompt Privilege Escalation Vulnerability
References:
References:
- Cisco PIX Firewall Product Homepage (Cisco Systems)
- PIX Privilege Escalation Vulnerability ([email protected])
- Re: PIX Privilege Escalation Vulnerability (Eloy Paris
) - Re: Re: PIX Privilege Escalation Vulnerability ([email protected])
- Re: Re: PIX Privilege Escalation Vulnerability ([email protected])