QID 317216

Date Published: 2022-08-18

QID 317216: Cisco Adaptive Security Appliance (ASA) Software Clientless Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client-Side Request Smuggling Vulnerability (cisco-sa-asa-webvpn-LOeKsNmO)

A vulnerability in the Clientless SSL VPN (WebVPN) component of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks.

Affected Products
Cisco ASA Software earlier than Release 9.17(1) and had the Clientless SSL VPN feature enabled.

QID Detection Logic (Authenticated):
The check matches Cisco ASA OS version retrieved via Unix Auth using "version" command.

A successful exploit could allow the attacker to conduct browser-based attacks

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-asa-webvpn-LOeKsNmO for more information.

    CVEs related to QID 317216

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-asa-webvpn-LOeKsNmO URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-webvpn-LOeKsNmO