Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2007-02-22 CVE-2007-1072 Permissions, Privileges, and Access Controls vulnerability in Cisco products
The command line interface (CLI) in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier allows local users to obtain privileges or cause a denial of service via unspecified vectors.
local
low complexity
cisco CWE-264
7.2
2007-02-22 CVE-2007-1068 Credentials Management vulnerability in multiple products
The (1) TTLS CHAP, (2) TTLS MSCHAP, (3) TTLS MSCHAPv2, (4) TTLS PAP, (5) MD5, (6) GTC, (7) LEAP, (8) PEAP MSCHAPv2, (9) PEAP GTC, and (10) FAST authentication methods in Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client store transmitted authentication credentials in plaintext log files, which allows local users to obtain sensitive information by reading these files, aka CSCsg34423.
local
low complexity
cisco meetinghouse CWE-255
7.2
2007-02-22 CVE-2007-1067 Multiple vulnerability in Cisco 802.1X Authentication Deployment Products
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not properly parse commands, which allows local users to gain privileges via unspecified vectors, aka CSCsh30624.
local
low complexity
cisco meetinghouse
7.2
2007-02-22 CVE-2007-1066 Multiple vulnerability in Cisco 802.1X Authentication Deployment Products
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client use an insecure default Discretionary Access Control Lists (DACL) for the connection client GUI, which allows local users to gain privileges by injecting "a thread under ConnectionClient.exe," aka CSCsg20558.
local
low complexity
cisco meetinghouse
6.8
2007-02-22 CVE-2007-1065 Multiple vulnerability in Cisco 802.1X Authentication Deployment Products
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client allows local users to gain SYSTEM privileges via unspecified vectors in the supplicant, aka CSCsf15836.
local
low complexity
cisco meetinghouse
6.8
2007-02-22 CVE-2007-1064 Multiple vulnerability in Cisco 802.1X Authentication Deployment Products
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not drop privileges when the help facility in the supplicant GUI is invoked, which allows local users to gain privileges, aka CSCsf14120.
local
low complexity
cisco meetinghouse
6.8
2007-02-22 CVE-2007-1063 USE of Hard-Coded Credentials vulnerability in Cisco products
The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.
network
low complexity
cisco CWE-798
critical
10.0
2007-02-22 CVE-2007-1062 Improper Authentication vulnerability in Cisco products
The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time
network
low complexity
cisco CWE-287
critical
10.0
2007-02-16 CVE-2007-0968 Products Multiple Remote Denial Of Service vulnerability in Cisco
Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL protections.
network
low complexity
cisco
critical
9.0
2007-02-16 CVE-2007-0967 Products Multiple Remote Denial Of Service vulnerability in Cisco Firewall Services Module 3.1
Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.1) allows remote attackers to cause a denial of service (device reboot) via malformed SNMP requests.
network
low complexity
cisco
7.8