Cisco Firewall products contain a flaw that may allow a malicious user to gain authorised access to a vulnerable device. The issue is triggered when certain passwords change to a non-random value under certain circumstances. It is possible that the flaw may allow authorized users to be locked out and unauthorized users to gain access resulting in a loss of confidentiality and integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Other
Impact:
Loss of Integrity
Exploit:
Exploit Unavailable
Disclosure:
OSVDB Verified,
Vendor Verified
OSVDB:
Security Software
Technical
The flaw may cause the EXEC password, passwords of locally defined users, and the enable password in the startup configuration to be changed.
The flaw is triggered during a software crash or multiple users configuring a device concurrently.
Solution
Upgrade to version 7.0(5.1) or higher for Cisco PIX/ASA 7.0(x) series. Upgrade to version 7.1(2.5) or higher for Cisco PIX/ASA 7.1(x) series. Upgrade to version 3.1(2) or higher for Cisco Firewall Services Module.
It has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following vendor workaround(s):