SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-4312

Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user…

MEDIUM 6.8EPSS 0.32%

Does this matter?

Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.

Description

Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user passwords, and the enable password to be changed to a "non-random value" under certain circumstances, which causes administrators to be locked out and might allow attackers to gain access.

CVSS 2.0
6.8 MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
EPSS
0.32% probability · 25th percentile
CISA KEV
Not listed
Affected
cisco/pix firewall 501 · cisco/pix firewall 506 · cisco/pix firewall 515 · cisco/pix firewall 515e · cisco/pix firewall 520 · cisco/pix firewall 525 · cisco/pix firewall 535 · cisco/pix firewall software · cisco/adaptive security appliance
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.