Guest

Preview Tool

Cisco Bug: CSCuq28582 - Cisco ASA VPN Failover Commands Injection Vulnerability

Last Modified

Oct 10, 2017

Products (1)

  • Cisco ASA 5500-X Series Firewalls

Known Affected Releases

9.2(2)

Description (partial)

Symptom:
Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities:

    Cisco ASA SQL*NET Inspection Engine Denial of Service Vulnerability
    Cisco ASA VPN Denial of Service Vulnerability
    Cisco ASA IKEv2 Denial of Service Vulnerability
    Cisco ASA High Performance Monitor Denial of Service Vulnerability
    Cisco ASA GPRS Tunneling Protocol Inspection Engine Denial of Service Vulnerability
    Cisco ASA SunRPC Inspection Engine Denial of Service Vulnerability
    Cisco ASA DNS Inspection Engine Denial of Service Vulnerability
    Cisco ASA VPN Failover Command Injection Vulnerability
    Cisco ASA VNMC Command Input Validation Vulnerability
    Cisco ASA Local Path Inclusion Vulnerability
    Cisco ASA Clientless SSL VPN Information Disclosure and Denial of Service Vulnerability
    Cisco ASA Clientless SSL VPN Portal Customization Integrity Vulnerability
    Cisco ASA Smart Call Home Digital Certificate Validation Vulnerability

These vulnerabilities are independent of one another; a release that is affected by one of the vulnerabilities may not be affected by the others.

Successful exploitation of the Cisco ASA SQL*NET Inspection Engine Denial of Service Vulnerability, Cisco ASA VPN Denial of Service Vulnerability, Cisco ASA IKEv2 Denial of Service Vulnerability, Cisco ASA High Performance Monitor Denial of Service Vulnerability, Cisco ASA GPRS Tunneling Protocol Inspection Engine Denial of Service Vulnerability, Cisco ASA SunRPC Inspection Engine Denial of Service Vulnerability, and Cisco ASA DNS Inspection Engine Denial of Service Vulnerability may result in a reload of an affected device, leading to a denial of service (DoS) condition.

Successful exploitation of the Cisco ASA VPN Failover Command Injection Vulnerability, Cisco ASA VNMC Command Input Validation Vulnerability, and Cisco ASA Local Path Inclusion Vulnerability may result in full compromise of the affected system.

Successful exploitation of the Cisco ASA Clientless SSL VPN Information Disclosure and Denial of Service Vulnerability may result in the disclosure of internal information or, in some cases, a reload of the affected system.

Successful exploitation of the Cisco ASA Clientless SSL VPN Portal Customization Integrity Vulnerability may result in a compromise of the Clientless SSL VPN portal, which may lead to several types of attacks, which are not limited to cross-site scripting (XSS), stealing of credentials, or redirects of users to malicious web pages.

Successful exploitation of the Cisco ASA Smart Call Home Digital Certificate Validation Vulnerability may result in a digital certificate validation bypass, which could allow the attacker to bypass digital certificate authentication and gain access inside the network via remote access VPN or management access to the affected system via the Cisco Adaptive Security Device Management (ASDM).

Cisco has released free software updates that address these vulnerabilities. Workarounds that mitigate some of these vulnerabilities are available.

This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141008-asa

Conditions:
See published Cisco Security Advisory
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.