CVE-2006-4312
Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user…
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user passwords, and the enable password to be changed to a "non-random value" under certain circumstances, which causes administrators to be locked out and might allow attackers to gain access.
- CVSS 2.0
- 6.8 MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Affected
- cisco/pix firewall 501 · cisco/pix firewall 506 · cisco/pix firewall 515 · cisco/pix firewall 515e · cisco/pix firewall 520 · cisco/pix firewall 525 · cisco/pix firewall 535 · cisco/pix firewall software · cisco/adaptive security appliance
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21616
- http://securitytracker.com/id?1016738
- http://securitytracker.com/id?1016739
- http://securitytracker.com/id?1016740
- http://www.cisco.com/warp/public/707/cisco-sa-20060823-firewall.shtmlVendor Advisory
- http://www.osvdb.org/28143
- http://www.securityfocus.com/bid/19681
- http://www.vupen.com/english/advisories/2006/3367
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28540
- http://secunia.com/advisories/21616
- http://securitytracker.com/id?1016738
- http://securitytracker.com/id?1016739
- http://securitytracker.com/id?1016740
- http://www.cisco.com/warp/public/707/cisco-sa-20060823-firewall.shtmlVendor Advisory
- http://www.osvdb.org/28143
- http://www.securityfocus.com/bid/19681
- http://www.vupen.com/english/advisories/2006/3367
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28540
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.