QID 730132

Date Published: 2021-07-15

QID 730132: Cisco Adaptive Security Device Manager Remote Code Execution Vulnerability(cisco-sa-asdm-rce-gqjShXW)

A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated,
remote attacker to execute arbitrary code on a user's operating system.

Affected Products
Cisco ASDM releases 7.16.1 and earlier (according to BUGID CSCvw79912)

QID Detection Logic (Unauthenticated):
The QID sends a get request to /admin/public/index.html and fetches version information of ASDM of Cisco ASA device.

A successful exploit may require the attacker to perform a social engineering attack to persuade
the user to initiate communication from the Launcher to the ASDM.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution

    Customers are advised to refer to cisco-sa-asdm-rce-gqjShXW for more information.

    CVEs related to QID 730132

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-asdm-rce-gqjShXW URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asdm-rce-gqjShXW