CVE-2008-1246
Estado: ModificadaAlta (7.8)—
The Cisco PIX/ASA Finesse Operation System 7.1 and 7.2 allows local users to gain privileges by entering characters at the enable prompt, erasing these characters via the Backspace key, and then holding down the Backspace key for one second after erasing the final character. NOTE: third parties, including one who works for the vendor, have been unable to reproduce the flaw unless the enable password is blank
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 25
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://hackathology.blogspot.com/2008/01/pixasa-finesse-71-72-privilege.html
- http://www.gnucitizen.org/projects/router-hacking-challenge/
- http://www.securityfocus.com/archive/1/486938
- http://www.securityfocus.com/archive/1/486959
- http://www.securityfocus.com/archive/1/487051
- http://www.securityfocus.com/archive/1/487579
- http://www.securityfocus.com/archive/1/489009/100/0/threaded
- http://www.securityfocus.com/bid/27457
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41129
- http://hackathology.blogspot.com/2008/01/pixasa-finesse-71-72-privilege.html
- http://www.gnucitizen.org/projects/router-hacking-challenge/
- http://www.securityfocus.com/archive/1/486938
- http://www.securityfocus.com/archive/1/486959
- http://www.securityfocus.com/archive/1/487051
- http://www.securityfocus.com/archive/1/487579
- http://www.securityfocus.com/archive/1/489009/100/0/threaded
- http://www.securityfocus.com/bid/27457
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41129
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-1246",
"cveTags": [
{
"tags": [
"disputed"
],
"sourceIdentifier": "cve@mitre.org"
}
],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2008-1246",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-01-17T15:14:07.818917Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": true,
"exploitabilityScore": 3.1,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-03-10T17:44:00.000",
"references": [
{
"url": "http://hackathology.blogspot.com/2008/01/pixasa-finesse-71-72-privilege.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.gnucitizen.org/projects/router-hacking-challenge/",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/486938",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/486959",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/487051",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/487579",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/489009/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27457",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41129",
"source": "cve@mitre.org"
},
{
"url": "http://hackathology.blogspot.com/2008/01/pixasa-finesse-71-72-privilege.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.gnucitizen.org/projects/router-hacking-challenge/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/486938",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/486959",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/487051",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/487579",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/489009/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27457",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41129",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Cisco PIX/ASA Finesse Operation System 7.1 and 7.2 allows local users to gain privileges by entering characters at the enable prompt, erasing these characters via the Backspace key, and then holding down the Backspace key for one second after erasing the final character. NOTE: third parties, including one who works for the vendor, have been unable to reproduce the flaw unless the enable password is blank"
},
{
"lang": "es",
"value": "** DISPUTADA ** Cisco PIX/ASA Finesse Operation System 7.1 y 7.2 permite a usuarios locales ganar privilegios mediante la introducción de caracteres en el intérprete de comandos, borrando estos caracteres a través de la tecla de retroceso (Backspace) y posteriormente manteniendo pulsada la tecla de retroceso durante un segundo después de borrar el último caracter. NOTA: terceras partes, incluyendo una que trabaja para el proveedor, no han podido reproducir el fallo a no ser que la contraseña de habilitar esté en blanco."
}
],
"lastModified": "2026-06-16T22:51:20.937",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:pix_asa_finesse_operation_system:7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0ABC60F3-FFE4-4748-91DA-79AE2D3513FE"
},
{
"criteria": "cpe:2.3:o:cisco:pix_asa_finesse_operation_system:7.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "70DA769D-9961-444A-80C1-39B43EFD5C87"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}