QID 316989

Date Published: 2021-06-28

QID 316989: Cisco Firepower Threat Defense (FTD) Software Lasso SAML Implementation Vulnerability Affecting Cisco Products: June 2021(cisco-sa-lasso-saml-jun2021-DOXNRLkD)

On June 1, 2021, Lasso disclosed a security vulnerability in the Lasso Security Assertion Markup Language (SAML) Single Sign-On (SSO) library.

Affected Products
Cisco Firepower Threat Defense (FTD) Software
Affected feature: AnyConnect VPN (only when SSO is enabled)
Affected Versions:
Prior to 6.4.0.12
From 6.5.0 Prior to 6.6.5
From 6.7.0 Prior to 6.7.0.2
Note: Potential detection as cannot confirm Single Sign-On (SSO) feature is enabled.
FXOS is not supported.

QID Detection Logic (Authenticated):
The Qid checks for the Vulnerable version of Cisco FTD in the response of "version" command.

This vulnerability could allow an authenticated attacker to impersonate another authorized user when interacting with an application.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-lasso-saml-jun2021-DOXNRLkD for more information.

    CVEs related to QID 316989

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-lasso-saml-jun2021-DOXNRLkD URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lasso-saml-jun2021-DOXNRLkD