QID 317009
Date Published: 2021-08-19
QID 317009: Cisco Adaptive Security Appliance (ASA) VPN Authentication Bypass Vulnerability (cisco-sa-20090408-asa)
The Cisco ASA or Cisco PIX security appliance can be configured to override an account-disabled indication from a AAA server and
allow the user to log on anyway.
However, the user must provide the correct credentials in order to login to the VPN.
A vulnerability exists in the Cisco ASA and Cisco PIX security appliances where VPN users can bypass authentication when the override account feature is enabled.
Note: The override account feature was introduced in Cisco ASA software version 7.1(1)
Potential detection as cannot confirm if override account feature is enabled. No support for Cisco PIX security appliance.
Affected Products
Cisco ASA or Cisco PIX security appliances that are configured for IPsec or SSL-based remote access VPN and have the Override Account Disabled feature enabled running vulnerable versions :
From 7.1(1) Prior to 7.1(2)82
From 7.2 Prior to 7.2(4)27
From 8.0 Prior to 8.0(4)25
From 8.1 Prior to 8.1(2)15
QID Detection Logic (Authenticated):
The check matches Cisco ASA OS version retrieved via Unix Auth using "version" command.
Successful exploitation may lead to unauthorized access.
Customers are advised to refer to cisco-sa-20090408-asa for more information.Workaround:
The override account feature is enabled with the override-account-disable command in tunnel-group general-attributes configuration mode.
As a workaround, disable this feature using the no override-account-disable command.
- cisco-sa-20090408-asa -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090408-asa
CVEs related to QID 317009
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-20090408-asa |
|