1 results (0.009 seconds)

CVSS: 6.8EPSS: 0%CPEs: 2EXPL: 0

The Cisco PIX/ASA Finesse Operation System 7.1 and 7.2 allows local users to gain privileges by entering characters at the enable prompt, erasing these characters via the Backspace key, and then holding down the Backspace key for one second after erasing the final character. NOTE: third parties, including one who works for the vendor, have been unable to reproduce the flaw unless the enable password is blank ** DISPUTADA ** Cisco PIX/ASA Finesse Operation System 7.1 y 7.2 permite a usuarios locales ganar privilegios mediante la introducción de caracteres en el intérprete de comandos, borrando estos caracteres a través de la tecla de retroceso (Backspace) y posteriormente manteniendo pulsada la tecla de retroceso durante un segundo después de borrar el último caracter. NOTA: terceras partes, incluyendo una que trabaja para el proveedor, no han podido reproducir el fallo a no ser que la contraseña de habilitar esté en blanco. • http://hackathology.blogspot.com/2008/01/pixasa-finesse-71-72-privilege.html http://www.gnucitizen.org/projects/router-hacking-challenge http://www.securityfocus.com/archive/1/486938 http://www.securityfocus.com/archive/1/486959 http://www.securityfocus.com/archive/1/487051 http://www.securityfocus.com/archive/1/487579 http://www.securityfocus.com/archive/1/489009/100/0/threaded http://www.securityfocus.com/bid/27457 https://exchange.xforce.ibmcloud.com/vulnerabilities/41129 • CWE-264: Permissions, Privileges, and Access Controls •