First published: Sat Jan 20 2007(Updated: )
The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those devices to obtain sensitive information or generate incorrect information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Security Monitoring Analysis and Response System | =4.2.3 | |
Cisco Adaptive Security Device Manager | =5.2.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0397 is considered a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2007-0397, upgrade to Cisco Security Monitoring, Analysis and Response System version 4.2.3 or later, and Adaptive Security Device Manager version 5.2(2.54) or later.
CVE-2007-0397 affects Cisco Security Monitoring, Analysis and Response System versions prior to 4.2.3 and Adaptive Security Device Manager versions prior to 5.2(2.54).
CVE-2007-0397 can be exploited by remote attackers to spoof devices, allowing them to obtain sensitive information.
No, exploitation of CVE-2007-0397 can occur without user intervention, making it particularly dangerous.