Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-4786

15
FAUCET Score

CVE-2007-4786 describes an information disclosure vulnerability in Cisco Adaptive Security Appliance (ASA) software versions 7.0, 7.1, 7.2, and 8.0. When AAA is enabled and the "test aaa" command is used, the ASA composes log messages containing cleartext passwords, which are then sent to remote syslog servers or stored locally. This allows attackers with network access to intercept or retrieve sensitive authentication credentials. The vulnerability is rated Medium severity with a CVSS score of 5.3, indicating an attack vector requiring adjacent network access and high complexity to exploit, but with a high impact on confidentiality. There is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.0, < 7.0.7.1CPE matchmatch criteria
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
>= 7.1, < 7.1.2.61CPE matchmatch criteria
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
>= 7.2, < 7.2.2.34CPE matchmatch criteria
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
>= 8.0, < 8.0.2.11CPE matchmatch criteria
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.50%
Probability of exploitation in next 30 days
EPSS Percentile
39.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0050 is in the 90th percentile among its peer group of 1,749 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

ciscovendor investigatingvia nvd_reference
View patch

References

osvdb.org / 37499
Broken Link
secunia.com / advisories/26677
Broken LinkThird Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/36473
Third Party AdvisoryVDB Entry
tools.cisco.com / Support/BugToolKit/search/getBugDetails.do
Broken LinkVendor Advisory
kb.cert.org / vuls/id/563673
Third Party AdvisoryUS Government Resource
kb.cert.org / vuls/id/MIMG-74ZK93
Third Party AdvisoryUS Government Resource
securityfocus.com / bid/25548
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
vupen.com / english/advisories/2007/3076
Broken LinkThird Party Advisory