CVE-2014-2128
published 2014-04-10CVE-2014-2128: The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before…
PriorityP432medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.92%
77.8th percentile
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before 8.6(1.13), 9.0 before 9.0(3.8), and 9.1 before 9.1(3.2) allows remote attackers to bypass authentication via (1) a crafted cookie value within modified HTTP POST data or (2) a crafted URL, aka Bug ID CSCua85555.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | asa | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco·2014-04-09·CVSS 7.5
CVE-2014-2126 [HIGH] Multiple Vulnerabilities in Cisco ASA Software
Multiple Vulnerabilities in Cisco ASA Software
Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities:
Cisco ASA ASDM Privilege Escalation Vulnerability
Cisco ASA SSL VPN Privilege Escalation Vulnerability
Cisco ASA SSL VPN Authentication Bypass Vulnerability
Cisco ASA SIP Denial of Service Vulnerability
These vulnerabilities are independent of one another; a release that is
affected by one of the vulnerabilities may not be affected by the
others.
Successful exploitation of the Cisco ASA ASDM Privilege Escalation Vulnerability and the Cisco ASA SSL VPN Privilege Escalation Vulnerability may allow an attacker or an unprivileged user to elevate privileges and gain administrative access to the affected system.
Successful exploitation of the Cisco AS
Cisco
Cisco Adaptive Security Appliance SSL VPN Authentication Bypass Vulnerability
vendor_cisco·2014-04-09·CVSS 5.0
CVE-2014-2128 [MEDIUM] CWE-287 Cisco Adaptive Security Appliance SSL VPN Authentication Bypass Vulnerability
Cisco Adaptive Security Appliance SSL VPN Authentication Bypass Vulnerability
A vulnerability in the SSL VPN code could allow an unauthenticated, remote attacker to access
the SSL VPN portal web page.
The
vulnerability is due to improper handling of authentication cookies
when the Cisco ASA SSL VPN feature is enabled. An
attacker could exploit this vulnerability by manually modifying the HTTP
POST body with a forged cookie value or entering a crafted URL. An
exploit could allow the attacker to gain unauthenticated access to the SSL VPN Portal page. Depending on the SSL VPN configuration, the attacker may also start a VPN tunnel by using Cisco AnyConnect.
In all cases, the attacker may gain unauthorized access to internal network resources.
Cisco has confirmed the vulnerability in a secur
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco
CVE-2014-2128 Multiple Vulnerabilities in Cisco ASA Software
CVE-2014-2128: Multiple Vulnerabilities in Cisco ASA Software
Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities: Cisco ASA ASDM Privilege Escalation Vulnerability Cisco ASA SSL VPN Privilege Escalation Vulnerability Cisco ASA SSL VPN Authentication Bypass Vulnerability Cisco ASA SIP Denial of Service Vulnerability These vulnerabilities are independent of one another; a release that is affected by one of the vulnerabilities may not be affected by the others. Successful exploitation of the Cisco ASA ASDM Privilege Escalation Vulnerability and the Cisco ASA SSL VPN Privilege Escalation Vulnerability may allow an attacker or an unprivileged user to elevate privileges and gain administrative access to the affected system. Successful exploitation of th
GHSA
GHSA-9rf4-rh3m-rwm3: The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8
ghsa_unreviewed·2022-05-17
CVE-2014-2128 [MEDIUM] CWE-287 GHSA-9rf4-rh3m-rwm3: The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before 8.6(1.13), 9.0 before 9.0(3.8), and 9.1 before 9.1(3.2) allows remote attackers to bypass authentication via (1) a crafted cookie value within modified HTTP POST data or (2) a crafted URL, aka Bug ID CSCua85555.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-04-10
Published