Vulnerability Name: | CVE-2014-2128 (CCN-92385) | ||||||||
Assigned: | 2014-04-09 | ||||||||
Published: | 2014-04-09 | ||||||||
Updated: | 2014-04-10 | ||||||||
Summary: | The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before 8.6(1.13), 9.0 before 9.0(3.8), and 9.1 before 9.1(3.2) allows remote attackers to bypass authentication via (1) a crafted cookie value within modified HTTP POST data or (2) a crafted URL, aka Bug ID CSCua85555. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-2128 Source: CCN Type: SA57820 Cisco Adaptive Security Appliance (ASA) Multiple Vulnerabilities Source: CCN Type: cisco-sa-20140409-asa Multiple Vulnerabilities in Cisco ASA Software Source: CISCO Type: Vendor Advisory 20140409 Multiple Vulnerabilities in Cisco ASA Software Source: CCN Type: BID-66746 Cisco ASA Software SSL VPN Feature Authentication Bypass Vulnerability Source: XF Type: UNKNOWN cisco-asa-cve20142128-sec-bypass(92385) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |