QID 317003
Date Published: 2021-08-16
QID 317003: Cisco Adaptive Security Appliance (ASA) WebVPN Cross-Site Scripting Vulnerability(cisco-sa-20191002-asa-xss)
A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Adaptive Security Appliance (ASA)
could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against
a user of the web-based management interface of an affected device.
Affected Products
Cisco ASA Software when configured for WebVPN.
Prior to 9.6.4.31
From 9.71 Prior to 9.8.4.9
From 9.9 Prior to 9.9.2.56
From 9.10 Prior to 9.10.1.30
From 9.12 Prior to 9.12.2.9
From 9.13 Prior to 9.13.1
QID Detection Logic (Authenticated):
The check matches Cisco ASA OS version retrieved via Unix Auth using "version" command.
A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or
allow the attacker to access sensitive browser-based information.
Customers are advised to refer to cisco-sa-20191002-asa-xss for more information.
- cisco-sa-20191002-asa-xss -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191002-asa-xss
CVEs related to QID 317003
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-20191002-asa-xss |
|