QID 316988
Date Published: 2021-07-06
QID 316988: Cisco ESA, SMA,WSA Lasso SAML Implementation Vulnerability (cisco-sa-lasso-saml-jun2021-DOXNRLkD)
On June 1, 2021, Lasso disclosed a security vulnerability in the Lasso Security Assertion Markup Language (SAML) Single Sign-On (SSO) library.
Affected Products
1.Cisco Content Security Management Appliance (SMA)
Affected feature: Web-based management interface (only when SSO is enabled)
Affected Version:
Prior to 13.8.1
From 14.0 Prior to 14.1.0
2.Cisco Email Security Appliance (ESA)
Affected feature: Web-based management interface (only when SSO is enabled)
Affected Version: Prior to 14.0.0-692
3.Cisco Web Security Appliance (WSA) Prior to 14.0.1 (Sep 2021)
Note: Potential detection as cannot confirm Single Sign On (SSO) feature is enabled.
QID Detection Logic (Authenticated):
The Qid checks for the Vulnerable version of Cisco ESA,CSM,WSA in the response of "version" command.
This vulnerability could allow an authenticated attacker to impersonate another authorized user when interacting with an application.
Customers are advised to refer to cisco-sa-lasso-saml-jun2021-DOXNRLkD for more information.
- cisco-sa-lasso-saml-jun2021-DOXNRLkD -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lasso-saml-jun2021-DOXNRLkD
CVEs related to QID 316988
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-lasso-saml-jun2021-DOXNRLkD |
|