VulnerabilityModified
CVE-2001-1098
Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file.
LOW 2.1EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Affected
- cisco/pix firewall manager
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-10/0071.htmlExploit, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/639507Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/3419
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7265
- http://archives.neohapsis.com/archives/bugtraq/2001-10/0071.htmlExploit, Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/639507Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/3419
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7265
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.