>> Cisco Multiple Product SSL/TLS Certificate and SSH Public Key Validation Vulnerability
Title : Cisco Multiple Product SSL/TLS Certificate and SSH Public Key Validation Vulnerability VUPEN ID : VUPEN/ADV-2007-0245 CVE ID : CVE-2007-0397
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-19
Technical Description
A vulnerability has been identified in Cisco Security Monitoring, Analysis and Response System (CS-MARS) and Cisco Adaptive Security Device Manager (ASDM), which could be exploited by attackers to bypass security restrictions. This issue is due to a lack of validation of Secure Sockets Layer (SSL)/Transport Layer Security (TLS) certificates or Secure Shell (SSH) public keys presented by certain devices configured to connect to CS-MARS or ASDM, which could be exploited by attackers to impersonate a device that an affected product connects to, which could then be used to obtain sensitive information (e.g. login credentials) or submit false data to a vulnerable product.