Executive Summary
This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
| Informations | |||
|---|---|---|---|
| Name | CVE-2007-4786 | First vendor Publication | 2007-09-10 |
| Vendor | Cve | Last vendor Modification | 2011-03-07 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:A/AC:H/Au:S/C:C/I:N/A:N) | |||
|---|---|---|---|
| Cvss Base Score | 4.3 | Attack Range | Adjacent network |
| Cvss Impact Score | 6.9 | Attack Complexity | High |
| Cvss Expoit Score | 2.5 | Authentification | Requires single instance |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA is enabled, composes %ASA-5-111008 messages from the "test aaa" command with cleartext passwords and sends them over the network to a remote syslog server or places them in a local logging buffer, which allows context-dependent attackers to obtain sensitive information. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4786 |
CAPEC : Common Attack Pattern Enumeration & Classification
| id | Name |
|---|---|
| CAPEC-31 | Accessing/Intercepting/Modifying HTTP Cookies |
| CAPEC-37 | Lifting Data Embedded in Client Distributions |
| CAPEC-65 | Passively Sniff and Capture Application Code Bound for Authorized Client |
| CAPEC-102 | Session Sidejacking |
| CAPEC-117 | Data Interception Attacks |
| CAPEC-155 | Screen Temporary Files for Sensitive Information |
| CAPEC-157 | Sniffing Attacks |
| CAPEC-167 | Lifting Sensitive Data from the Client |
| CAPEC-204 | Lifting cached, sensitive data embedded in client distributions (thick or thin) |
| CAPEC-205 | Lifting credential(s)/key material embedded in client distributions (thick or... |
| CAPEC-258 | Passively Sniffing and Capturing Application Code Bound for an Authorized Cli... |
| CAPEC-259 | Passively Sniffing and Capturing Application Code Bound for an Authorized Cli... |
| CAPEC-260 | Passively Sniffing and Capturing Application Code Bound for an Authorized Cli... |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information |
| CWE-311 | Missing Encryption of Sensitive Data(CWE/SANS Top 25) |
| CWE-255 | Credentials Management |
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Hardware | 4 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 37499 | Cisco Adaptive Security Appliance (ASA) PIX Cleartext Password Remote Disclosure |
Internal Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2013-05-11 10:36:06 |
|

CVE-2007-4786
(Medium)







