CVE-2001-1098: Low severity Cisco PIX firewall manager vulnerability
Published Oct 10, 2001
·Updated
Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file.
Affected Software
1 affected component
Cisco PIX firewall manager=4.3\(2\)g
Remediation
Event History
Oct 10, 2001
CVE Published
04:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1098?
The severity of CVE-2001-1098 is considered moderate due to the exposure of the enable password in plaintext.
2
How do I fix CVE-2001-1098?
To fix CVE-2001-1098, ensure to upgrade the Cisco PIX Firewall Manager to a version that does not log sensitive information in plaintext.
3
Who is affected by CVE-2001-1098?
CVE-2001-1098 affects users of Cisco PIX Firewall Manager version 4.3(2)g.
4
What are the risks associated with CVE-2001-1098?
The risks associated with CVE-2001-1098 include unauthorized access to the firewall due to exposure of the plaintext enable password.
5
Can local users exploit CVE-2001-1098?
Yes, local users can exploit CVE-2001-1098 by reading the pfm.log file to obtain the enable password.