CVE Vulnerabilities

CVE-2009-1155

Improper Authentication

Published: Apr 09, 2009 | Modified: Apr 28, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2(4)27, 8.0 before 8.0(4)25, and 8.1 before 8.1(2)15, when AAA override-account-disable is entered in a general-attributes field, allow remote attackers to bypass authentication and establish a VPN session to an ASA device via unspecified vectors.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Adaptive_security_appliance_5500 Cisco 7.1 (including) 7.1 (including)
Adaptive_security_appliance_5500 Cisco 7.2 (including) 7.2 (including)
Adaptive_security_appliance_5500 Cisco 8.0 (including) 8.0 (including)
Adaptive_security_appliance_5500 Cisco 8.1 (including) 8.1 (including)
Pix Cisco 7.1 (including) 7.1 (including)
Pix Cisco 7.2 (including) 7.2 (including)
Pix Cisco 8.0 (including) 8.0 (including)
Pix Cisco 8.1 (including) 8.1 (including)

Potential Mitigations

References