CVE-2009-1155

Cisco Adaptive Security Appliance 5500 - Authentication Bypass

Title source: rule

Description

Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2(4)27, 8.0 before 8.0(4)25, and 8.1 before 8.1(2)15, when AAA override-account-disable is entered in a general-attributes field, allow remote attackers to bypass authentication and establish a VPN session to an ASA device via unspecified vectors.

Scores

EPSS 0.0086
EPSS Percentile 74.8%

Classification

CWE
CWE-287
Status draft

Affected Products (8)

cisco/adaptive_security_appliance_5500
cisco/adaptive_security_appliance_5500
cisco/adaptive_security_appliance_5500
cisco/adaptive_security_appliance_5500
cisco/pix
cisco/pix
cisco/pix
cisco/pix

Timeline

Published Apr 09, 2009
Tracked Since Feb 18, 2026