A vulnerability in the authorization subsystem of cisco adaptive security appliance asa software could allow an authenticated but unprivileged levels 0 and 1 remote attacker to perform privileged actions by using the web management interface.
Cisco adaptive security appliance software version.
Release notes for the cisco asa device package software version 1 3 10 for aci 28 aug 2018.
Xml examples for the cisco asa device package software version 1 3 12 for aci.
An attacker could exploit this vulnerability.
Release notes for the cisco asa device package software version 1 2 12 for aci 17 may 2019.
The vulnerability is due to insufficient csrf protections for the web based management interface on an affected device.
A vulnerability in the web based management interface of cisco adaptive security appliance asa software could allow an unauthenticated remote attacker to conduct a cross site request forgery csrf attack on an affected system.
The vulnerability is due to improper validation of user privileges when using the web management interface.
It delivers enterprise class firewall capabilities for asa devices in an array of form factors standalone appliances blades and virtual appliances for any distributed network environment.
Asa software also integrates with other critical security technologies to deliver comprehensive.
Cisco adaptive security appliance software and firepower threat defense software web services read only path traversal vulnerability 27 aug 2020 cisco ios xe software and cisco asa 5500 x series adaptive security appliance ipsec denial of service vulnerability 25 aug 2020.
Release notes for the cisco asa device package software version 1 3 12 for aci 17 may 2019.
Release notes for the cisco asa device package software version 1 3 11 for aci 02 nov 2018.