QID 317406
QID 317406: Cisco Adaptive Security Appliance (ASA) AnyConnect Access Control List Bypass Vulnerabilities (cisco-sa-asaftd-ac-acl-bypass-bwd7q6Gb)
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device.
Affected Products
ASA Version 9.8.4 prior to 9.12.4.58
ASA Version 9.14.1 prior to 9.16.4.19
ASA Version 9.17.1 prior to 9.17.1.33
ASA Version 9.18.1 prior to 9.18.3.39
ASA Version 9.19.1 prior to 9.19.1.12
Note: This QID does not check for conditions mention in advisory. Hence kept as Practice.
QID Detection Logic (Authenticated):
The check matches Cisco ASA OS version retrieved via Unix Auth using version command.
A successful exploit could allow the attacker to bypass the interface ACL and access resources that should be protected.
Customers are advised to refer to cisco-sa-asaftd-ac-acl-bypass-bwd7q6Gb for more information.
- cisco-sa-asaftd-ac-acl-bypass-bwd7q6Gb -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ac-acl-bypass-bwd7q6Gb
CVEs related to QID 317406
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-asaftd-ac-acl-bypass-bwd7q6Gb |
|