CVE-2007-0397

UnknownEPSS 2.81%

Last modified

CVE-2007-0397 is a vulnerability of currently unknown severity. The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those devices to obtain sensitive information or generate incorrect information.. EPSS estimates a 2.81% chance of exploitation in the next 30 days.

Description

The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those devices to obtain sensitive information or generate incorrect information.

Metrics

EPSS Probability
2.81%

84.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CiscoSecurity Monitoring Analysis And Response System4.2.3
CiscoAdaptive Security Appliance Device Manager5.2.53

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-0397?
The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those devices to obtain sensitive information or generate incorrect information.
How severe is CVE-2007-0397?
Severity scoring for CVE-2007-0397 is pending analysis. The EPSS model estimates a 2.81% probability of exploitation in the next 30 days.
How do I fix CVE-2007-0397?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-0397?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST