{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:02:55Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20070214-CVE-2007-0960","slug":"cisco-sa-20070214-cve-2007-0960","vendor":"Cisco","title":"Cisco PIX and ASA LOCAL Method Privilege Escalation Vulnerability","summary":"Cisco PIX 500 Series Security Appliances and Cisco ASA 5500 Series Adaptive Security Appliances (ASA) contain a vulnerability that&nbsp;could allow an authenticated, remote attacker to gain elevated privileges on the device. The vulnerability only exists on devices using LOCAL method for user authentication.&nbsp; The attacker must also be defined in the local database with a privilege of zero and be able to authenticate to the device.&nbsp; If these conditions are met, an attacker could grant themselves administrative privileges. The vendor has given this issue a CVSS score to reflect the availability of functional exploit code; however, the code is not known to be publicly available. Cisco has confirmed this vulnerability and updated software is available. In order to exploit this vulnerability, an attacker must be defined in the local database with a privilege level of zero and be able to authenticate to the affected device.&nbsp; These conditions greatly reduce the likelihood of attacks, as only trusted users should be defined in the local database.&nbsp; It should also be noted that the affected devices are not vulnerable in their default configurations.","severity":"Medium","published_at":"2007-02-14T23:06:59Z","updated_at":"2007-02-14T23:06:59Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20070214-CVE-2007-0960","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20070214-CVE-2007-0960/csaf/Cisco-SA-20070214-CVE-2007-0960.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0},"cves":[{"id":"CVE-2007-0960","kev":false}],"public_evidence":[{"product":{"name":"Cisco PIX/ASA","slug":"cisco-pix-asa","vendor":"Cisco"},"cve":{"id":"CVE-2007-0960"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T04:30:19Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco PIX/ASA","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"published_at":"2007-02-14T23:06:59Z","updated_at":"2007-02-14T23:06:59Z","advisory_updated_at":"2007-02-14T23:06:59Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20070214-CVE-2007-0960","row_display_order":1}]}