Vulnerability Name: CVE-2013-5510 (CCN-87775) Assigned: 2013-10-09 Published: 2013-10-09 Updated: 2016-11-01 Summary: The remote-access VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.6.x before 8.6(1.12), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.5), when an override-account-disable option is enabled, does not properly parse AAA LDAP responses, which allows remote attackers to bypass authentication via a VPN connection attempt, aka Bug ID CSCug83401. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): NoneAvailibility (A): None
CVSS v2 Severity: 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N )3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N )3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
Vulnerability Type: CWE-287 Vulnerability Consequences: Bypass Security References: Source: MITRE Type: CNACVE-2013-5510 Source: CCN Type: cisco-sa-20131009-asaMultiple Vulnerabilities in Cisco ASA Software Source: CISCO Type: Vendor Advisory20131009 Multiple Vulnerabilities in Cisco ASA Software Source: CISCO Type: Vendor Advisory20131213 Remote Access VPN Authentication Bypass Vulnerability Source: CCN Type: OSVDB ID: 98264Cisco Adaptive Security Appliance (ASA) LDAP Response Packet Handling Authentication Bypass Information Disclosure Source: CCN Type: BID-62914Cisco Adaptive Security Appliance Software CVE-2013-5510 Authentication Bypass Vulnerability Source: XF Type: UNKNOWNcisco-asa-cve20135510-sec-bypass(87775) Vulnerable Configuration: Configuration 1 :cpe:/a:cisco:adaptive_security_appliance_software:7.0:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(0):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(1):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(2):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(4):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(5):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(5.2):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(6):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(6.7):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(7):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0(8):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0.1.4:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0.2:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0.4:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0.4.3:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0.5:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0.6:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0.7:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0.8:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.0.8:interim:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.1(2):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.1(2.5):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.1(2.27):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.1(2.48):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.1(2.49):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.1(5):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.1.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.1.2:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(1):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(1.22):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.5):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.7):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.8):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.10):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.14):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.15):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.16):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.17):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.18):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.19):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(2.48):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(3):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(4):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:7.2(5):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.0:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.0(2):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.0(3):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.0(4):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.0(5):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.0(5.28):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.0(5.31):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.0.2:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.0.3:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.0.4:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.0.5:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.2:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.2(1):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.2(2):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.2(3):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.2(3.9):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.2(4):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.2(4.1):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.2(4.4):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.2(5):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.2(5.35):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.2(5.38):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4(1):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4(1.11):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4(2):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4(2.11):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4(3):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4(4.11):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4(5):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.6:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.6(1):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.6(1.10):*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1(1.7):*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:cisco:adaptive_security_appliance:-:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
cisco adaptive security appliance software 7.0
cisco adaptive security appliance software 7.0(0)
cisco adaptive security appliance software 7.0(1)
cisco adaptive security appliance software 7.0(2)
cisco adaptive security appliance software 7.0(4)
cisco adaptive security appliance software 7.0(5)
cisco adaptive security appliance software 7.0(5.2)
cisco adaptive security appliance software 7.0(6)
cisco adaptive security appliance software 7.0(6.7)
cisco adaptive security appliance software 7.0(7)
cisco adaptive security appliance software 7.0(8)
cisco adaptive security appliance software 7.0.1
cisco adaptive security appliance software 7.0.1.4
cisco adaptive security appliance software 7.0.2
cisco adaptive security appliance software 7.0.4
cisco adaptive security appliance software 7.0.4.3
cisco adaptive security appliance software 7.0.5
cisco adaptive security appliance software 7.0.6
cisco adaptive security appliance software 7.0.7
cisco adaptive security appliance software 7.0.8
cisco adaptive security appliance software 7.0.8 interim
cisco adaptive security appliance software 7.1
cisco adaptive security appliance software 7.1(2)
cisco adaptive security appliance software 7.1(2.5)
cisco adaptive security appliance software 7.1(2.27)
cisco adaptive security appliance software 7.1(2.48)
cisco adaptive security appliance software 7.1(2.49)
cisco adaptive security appliance software 7.1(5)
cisco adaptive security appliance software 7.1.1
cisco adaptive security appliance software 7.1.2
cisco adaptive security appliance software 7.2
cisco adaptive security appliance software 7.2(1)
cisco adaptive security appliance software 7.2(1.22)
cisco adaptive security appliance software 7.2(2)
cisco adaptive security appliance software 7.2(2.5)
cisco adaptive security appliance software 7.2(2.7)
cisco adaptive security appliance software 7.2(2.8)
cisco adaptive security appliance software 7.2(2.10)
cisco adaptive security appliance software 7.2(2.14)
cisco adaptive security appliance software 7.2(2.15)
cisco adaptive security appliance software 7.2(2.16)
cisco adaptive security appliance software 7.2(2.17)
cisco adaptive security appliance software 7.2(2.18)
cisco adaptive security appliance software 7.2(2.19)
cisco adaptive security appliance software 7.2(2.48)
cisco adaptive security appliance software 7.2(3)
cisco adaptive security appliance software 7.2(4)
cisco adaptive security appliance software 7.2(5)
cisco adaptive security appliance software 8.0
cisco adaptive security appliance software 8.0(2)
cisco adaptive security appliance software 8.0(3)
cisco adaptive security appliance software 8.0(4)
cisco adaptive security appliance software 8.0(5)
cisco adaptive security appliance software 8.0(5.28)
cisco adaptive security appliance software 8.0(5.31)
cisco adaptive security appliance software 8.0.2
cisco adaptive security appliance software 8.0.3
cisco adaptive security appliance software 8.0.4
cisco adaptive security appliance software 8.0.5
cisco adaptive security appliance software 8.1
cisco adaptive security appliance software 8.2
cisco adaptive security appliance software 8.2(1)
cisco adaptive security appliance software 8.2(2)
cisco adaptive security appliance software 8.2(3)
cisco adaptive security appliance software 8.2(3.9)
cisco adaptive security appliance software 8.2(4)
cisco adaptive security appliance software 8.2(4.1)
cisco adaptive security appliance software 8.2(4.4)
cisco adaptive security appliance software 8.2(5)
cisco adaptive security appliance software 8.2(5.35)
cisco adaptive security appliance software 8.2(5.38)
cisco adaptive security appliance software 8.4
cisco adaptive security appliance software 8.4(1)
cisco adaptive security appliance software 8.4(1.11)
cisco adaptive security appliance software 8.4(2)
cisco adaptive security appliance software 8.4(2.11)
cisco adaptive security appliance software 8.4(3)
cisco adaptive security appliance software 8.4(4.11)
cisco adaptive security appliance software 8.4(5)
cisco adaptive security appliance software 8.6
cisco adaptive security appliance software 8.6(1)
cisco adaptive security appliance software 8.6(1.10)
cisco adaptive security appliance software 9.0
cisco adaptive security appliance software 9.1
cisco adaptive security appliance software 9.1(1.7)
cisco adaptive security appliance -