Vulnerability CVE-2008-3815


Published: 2008-10-23   Modified: 2012-02-12

Description:
Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)3, 7.1 before 7.1(2)78, 7.2 before 7.2(4)16, 8.0 before 8.0(4)6, and 8.1 before 8.1(1)13, when configured as a VPN using Microsoft Windows NT Domain authentication, allows remote attackers to bypass VPN authentication via unknown vectors.

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Cisco -> Asa 5500 
Cisco -> PIX 

 References:
http://xforce.iss.net/xforce/xfdb/46024
http://www.vupen.com/english/advisories/2008/2899
http://www.securitytracker.com/id?1021090
http://www.securitytracker.com/id?1021089
http://www.securityfocus.com/bid/31864
http://www.cisco.com/en/US/products/products_security_advisory09186a0080a183ba.shtml
http://secunia.com/advisories/32360
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5983

Copyright 2024, cxsecurity.com

 

Back to Top