Cisco ASA Software SSL VPN Feature Authentication Bypass Vulnerability
BID:66746
Info
Cisco ASA Software SSL VPN Feature Authentication Bypass Vulnerability
| Bugtraq ID: | 66746 |
| Class: | Design Error |
| CVE: |
CVE-2014-2128 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2014 12:00AM |
| Updated: | Apr 09 2014 12:00AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco ASA Software SSL VPN Feature Authentication Bypass Vulnerability
Cisco ASA Software is prone to a remote authentication-bypass vulnerability.
Exploiting this issue could allow an attacker to bypass certain security restrictions and gain unauthenticated access to the SSL VPN Portal page.
This issue is tracked by Cisco Bug ID CSCua85555.
Cisco ASA Software is prone to a remote authentication-bypass vulnerability.
Exploiting this issue could allow an attacker to bypass certain security restrictions and gain unauthenticated access to the SSL VPN Portal page.
This issue is tracked by Cisco Bug ID CSCua85555.
Exploit / POC
Cisco ASA Software SSL VPN Feature Authentication Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Cisco ASA Software SSL VPN Feature Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco ASA Software SSL VPN Feature Authentication Bypass Vulnerability
References:
References:
- Cisco Homepage (Cisco )