Cisco Adaptive Security Appliance (ASA) Software CVE-2014-3393 Remote Security Bypass Vulnerability
BID:70309
Info
Cisco Adaptive Security Appliance (ASA) Software CVE-2014-3393 Remote Security Bypass Vulnerability
| Bugtraq ID: | 70309 |
| Class: | Design Error |
| CVE: |
CVE-2014-3393 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 2014 12:00AM |
| Updated: | Oct 08 2014 12:00AM |
| Credit: | Alec Stuart-Muirk |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Adaptive Security Appliance (ASA) Software CVE-2014-3393 Remote Security Bypass Vulnerability
Cisco Adaptive Security Appliance (ASA) Software is prone to a remote security-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass Clientless SSL VPN authentication and modify the portal content.
This issue is tracked by Cisco Bug ID CSCup36829.
Cisco Adaptive Security Appliance (ASA) Software is prone to a remote security-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass Clientless SSL VPN authentication and modify the portal content.
This issue is tracked by Cisco Bug ID CSCup36829.
Exploit / POC
Cisco Adaptive Security Appliance (ASA) Software CVE-2014-3393 Remote Security Bypass Vulnerability
Attackers can use readily available network utilities to exploit this issue.
Attackers can use readily available network utilities to exploit this issue.
Solution / Fix
Cisco Adaptive Security Appliance (ASA) Software CVE-2014-3393 Remote Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Adaptive Security Appliance (ASA) Software CVE-2014-3393 Remote Security Bypass Vulnerability
References:
References:
- Cisco Homepage (Cisco)