CVE-2008-2736: Infoleak
Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0(3)15, 8.0(3)16, 8.1(1)4, and 8.1(1)5, when configured as a clientless SSL VPN endpoint, allows remote attackers to obtain usernames and passwords via unknown vectors, aka Bug ID CSCsq45636.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2736?
CVE-2008-2736 has a high severity rating as it allows remote attackers to obtain sensitive usernames and passwords.
How do I fix CVE-2008-2736?
To mitigate CVE-2008-2736, update the Cisco Adaptive Security Appliance (ASA) to a patched version that is not affected by this vulnerability.
Which devices are affected by CVE-2008-2736?
CVE-2008-2736 primarily affects Cisco Adaptive Security Appliance 5500 devices running specific versions of the software, namely 8.0(3)15, 8.0(3)16, 8.1(1)4, and 8.1(1)5.
What types of attacks are possible with CVE-2008-2736?
CVE-2008-2736 allows remote attackers to exploit unspecified vectors to gain access to usernames and passwords.
Is there a known workaround for CVE-2008-2736?
There are no specific workarounds for CVE-2008-2736; upgrading to a safe version of the software is the recommended approach.