SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-1160

Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)1, 7.1 before 7.1(2)74, 7.2 before 7.2(4)9, and 8.0 before 8.0(4)5 do not properly implement the implicit deny statement, which might allow remote…

MEDIUM 4.3EPSS 1.14%

Does this matter?

Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.

Description

Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)1, 7.1 before 7.1(2)74, 7.2 before 7.2(4)9, and 8.0 before 8.0(4)5 do not properly implement the implicit deny statement, which might allow remote attackers to successfully send packets that bypass intended access restrictions, aka Bug ID CSCsq91277.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS
1.14% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
cisco/adaptive security appliance 5500 · cisco/pix
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.