QID 316990
Date Published: 2021-06-28
QID 316990: Cisco Adaptive Security Appliance (ASA) Software Lasso SAML Implementation Vulnerability
On June 1, 2021, Lasso disclosed a security vulnerability in the Lasso Security Assertion Markup Language (SAML) Single Sign-On (SSO) library.
Affected Products
Cisco Adaptive Security Appliance (ASA) Software if running a vulnerable release:
Affected features: Clientless WebVPN and AnyConnect VPN (only when SSO is enabled)
Prior To 9.8.4.39
From 9.9 Prior To 9.12.4.24
From 9.13 Prior To 9.14.3.0
From 9.14 Prior To 9.15.1.15
From 9.16 Prior To 9.16.1.3
QID Detection Logic (Authenticated):
The check matches Cisco ESA OS version retrieved via Unix Auth using "version" command.
This vulnerability could allow an authenticated attacker to impersonate another authorized user when interacting with an application.
Customers are advised to refer to cisco-sa-lasso-saml-jun2021-DOXNRLkD for more information.
- cisco-sa-lasso-saml-jun2021-DOXNRLkD -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-lasso-saml-jun2021-DOXNRLkD
CVEs related to QID 316990
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-lasso-saml-jun2021-DOXNRLkD |
|