4.3
CVSSv2

CVE-2014-3410

Published: 20/12/2014 Updated: 11/08/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The syslog-management subsystem in Cisco Adaptive Security Appliance (ASA) Software allows remote malicious users to obtain an administrator password by waiting for an administrator to copy a file, and then (1) sniffing the network for a syslog message or (2) reading a syslog message in a file on a syslog server, aka Bug IDs CSCuq22357 and CSCur41860.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco adaptive security appliance software -

Vendor Advisories

A vulnerability in the syslog management subsystem of devices running Cisco Adaptive Security Appliance (ASA) Software may allow an unauthenticated, remote attacker to access sensitive information The vulnerability is due to improper sanitization of syslog messages An attacker could exploit this vulnerability by convincing an ASA administrator t ...