Cisco PIX and ASA Windows NT Domain VPN Authentication Bypass Vulnerability
BID:31864
Info
Cisco PIX and ASA Windows NT Domain VPN Authentication Bypass Vulnerability
| Bugtraq ID: | 31864 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-3815 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2008 12:00AM |
| Updated: | Oct 22 2008 07:56PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Cisco PIX/ASA 8.1 Cisco PIX/ASA 8.0 Cisco PIX/ASA 7.2 Cisco PIX/ASA 7.1 Cisco PIX/ASA 7.0 |
| Not Vulnerable: |
Cisco PIX/ASA 8.1(1)13 Cisco PIX/ASA 8.0(4)6 Cisco PIX/ASA 7.2(4)16 Cisco PIX/ASA 7.1(2)78 Cisco PIX/ASA 7.0(8)3 |
Discussion
Cisco PIX and ASA Windows NT Domain VPN Authentication Bypass Vulnerability
Cisco PIX and ASA is prone to an authentication-bypass vulnerability.
Remote attackers can exploit this issue to gain unauthorized access to the affected devices. Successfully exploiting this issue will lead to other attacks.
This issue is being monitored by Cisco Bug ID CSCsj25896.
Cisco PIX and ASA is prone to an authentication-bypass vulnerability.
Remote attackers can exploit this issue to gain unauthorized access to the affected devices. Successfully exploiting this issue will lead to other attacks.
This issue is being monitored by Cisco Bug ID CSCsj25896.
Exploit / POC
Cisco PIX and ASA Windows NT Domain VPN Authentication Bypass Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Cisco PIX and ASA Windows NT Domain VPN Authentication Bypass Vulnerability
Solution:
The vendor has released updates and an advisory. Please see the referenced advisory for more information.
Solution:
The vendor has released updates and an advisory. Please see the referenced advisory for more information.
References
Cisco PIX and ASA Windows NT Domain VPN Authentication Bypass Vulnerability
References:
References: