QID 730132
Date Published: 2021-07-15
QID 730132: Cisco Adaptive Security Device Manager Remote Code Execution Vulnerability(cisco-sa-asdm-rce-gqjShXW)
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated,
remote attacker to execute arbitrary code on a user's operating system.
Affected Products
Cisco ASDM releases 7.16.1 and earlier (according to BUGID CSCvw79912)
QID Detection Logic (Unauthenticated):
The QID sends a get request to /admin/public/index.html and fetches version information of ASDM of Cisco ASA device.
A successful exploit may require the attacker to perform a social engineering attack to persuade
the user to initiate communication from the Launcher to the ASDM.
Solution
Customers are advised to refer to cisco-sa-asdm-rce-gqjShXW for more information.
Vendor References
- cisco-sa-asdm-rce-gqjShXW -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asdm-rce-gqjShXW
CVEs related to QID 730132
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-asdm-rce-gqjShXW |
|