CVE Vulnerabilities

CVE-2009-1155

Improper Authentication

Published: Apr 09, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2(4)27, 8.0 before 8.0(4)25, and 8.1 before 8.1(2)15, when AAA override-account-disable is entered in a general-attributes field, allow remote attackers to bypass authentication and establish a VPN session to an ASA device via unspecified vectors.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Adaptive_security_appliance_5500Cisco7.1 (including)7.1 (including)
Adaptive_security_appliance_5500Cisco7.2 (including)7.2 (including)
Adaptive_security_appliance_5500Cisco8.0 (including)8.0 (including)
Adaptive_security_appliance_5500Cisco8.1 (including)8.1 (including)
PixCisco7.1 (including)7.1 (including)
PixCisco7.2 (including)7.2 (including)
PixCisco8.0 (including)8.0 (including)
PixCisco8.1 (including)8.1 (including)

Potential Mitigations

References