QID 316990

Date Published: 2021-06-28

QID 316990: Cisco Adaptive Security Appliance (ASA) Software Lasso SAML Implementation Vulnerability

On June 1, 2021, Lasso disclosed a security vulnerability in the Lasso Security Assertion Markup Language (SAML) Single Sign-On (SSO) library.

Affected Products
Cisco Adaptive Security Appliance (ASA) Software if running a vulnerable release:
Affected features: Clientless WebVPN and AnyConnect VPN (only when SSO is enabled)
Prior To 9.8.4.39
From 9.9 Prior To 9.12.4.24
From 9.13 Prior To 9.14.3.0
From 9.14 Prior To 9.15.1.15
From 9.16 Prior To 9.16.1.3

QID Detection Logic (Authenticated):
The check matches Cisco ESA OS version retrieved via Unix Auth using "version" command.

This vulnerability could allow an authenticated attacker to impersonate another authorized user when interacting with an application.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-lasso-saml-jun2021-DOXNRLkD for more information.

    CVEs related to QID 316990

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-lasso-saml-jun2021-DOXNRLkD URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lasso-saml-jun2021-DOXNRLkD