CVE-2014-0739
published 2014-02-22CVE-2014-0739: Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass sec_db…
PriorityP428medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.15%
63.4th percentile
Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass sec_db authentication and provide certain pass-through services to untrusted devices via a crafted configuration-file TFTP request, aka Bug ID CSCuj66766.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance Phone Proxy sec_db Race Condition Vulnerability
vendor_cisco·2014-02-21·CVSS 4.3
CVE-2014-0739 [MEDIUM] CWE-362 Cisco Adaptive Security Appliance Phone Proxy sec_db Race Condition Vulnerability
Cisco Adaptive Security Appliance Phone Proxy sec_db Race Condition Vulnerability
A vulnerability in the TFTP request function of the Phone Proxy feature of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to pass traffic from an untrusted phone through the ASA.
The vulnerability is due to a limitation in processing the TFTP request for a configuration file. An attacker could exploit this vulnerability by sending a crafted TFTP request for a phone configuration file. An exploit could allow the attacker to pass traffic from an untrusted phone through the ASA.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
Cisco indicates through the CVSS score that proof-of-concept exploit code exists;
GHSA
GHSA-xhmg-fcjg-c5rx: Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9
ghsa_unreviewed·2022-05-13
CVE-2014-0739 [MEDIUM] CWE-287 GHSA-xhmg-fcjg-c5rx: Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9
Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass sec_db authentication and provide certain pass-through services to untrusted devices via a crafted configuration-file TFTP request, aka Bug ID CSCuj66766.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-02-22
Published