Overview
The Cisco Adaptive Security Appliance (ASA) firewall may log user credentials, including passwords, as plain text when AAA authentication is enabled.
Description
The Cisco Adapative Security Appliance (ASA) is a firewall with Intrusion Protection System (IPS), Stateful Packet Inspection (SPI), and routing features. The Cisco ASA includes Authentication, Authorization and Accounting (AAA) support that allows adminsitrators and users to use a single set of credentials to manage multiple devices. |
Impact
Authentication credentials may be stored in plain text, possibly on remote servers. The credentials may also be sent unencrypted over the network. |
Solution
See the "Sytems Affected" section of this document for more information about obtaining updates. |
The following workarounds may partially mitigate this vulnerability:
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
Temporal | 0 | E:ND/RL:ND/RC:ND |
Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
This vulnerability was reported and discovered by Lisa Sittler of CERT/CC.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | None |
Severity Metric: | 0.13 |
Date Public: | 2007-09-05 |
Date First Published: | 2007-09-05 |
Date Last Updated: | 2007-10-01 23:05 UTC |
Document Revision: | 21 |