CVE-2013-5509Improper Input Validation in Cisco Adaptive Security Appliance Software

Severity
10.0CRITICALNVD
EPSS
1.4%
top 19.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Latest updateMay 17

Description

The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0 before 9.0(2.6) and 9.1 before 9.1(2) allows remote attackers to bypass authentication, and obtain VPN access or administrative access, via a crafted X.509 client certificate, aka Bug ID CSCuf52468.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-m6gf-4gcj-j6c4: The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 92022-05-17
CVEList
CVE-2013-5509: The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 92013-10-13

📋Vendor Advisories

1
Cisco
Multiple Vulnerabilities in Cisco ASA Software2013-10-09
CVE-2013-5509 — Improper Input Validation in Cisco | cvebase