CVE-2007-4786 describes an information disclosure vulnerability in Cisco Adaptive Security Appliance (ASA) software versions 7.0, 7.1, 7.2, and 8.0. When AAA is enabled and the "test aaa" command is used, the ASA composes log messages containing cleartext passwords, which are then sent to remote syslog servers or stored locally. This allows attackers with network access to intercept or retrieve sensitive authentication credentials. The vulnerability is rated Medium severity with a CVSS score of 5.3, indicating an attack vector requiring adjacent network access and high complexity to exploit, but with a high impact on confidentiality. There is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0, < 7.0.7.1CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 7.1, < 7.1.2.61CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 7.2, < 7.2.2.34CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.0.2.11CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.