CVE-2014-2128Improper Authentication in Cisco Adaptive Security Appliance Software

Severity
5.0MEDIUMNVD
EPSS
0.2%
top 51.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateMay 17

Description

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before 8.6(1.13), 9.0 before 9.0(3.8), and 9.1 before 9.1(3.2) allows remote attackers to bypass authentication via (1) a crafted cookie value within modified HTTP POST data or (2) a crafted URL, aka Bug ID CSCua85555.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-9rf4-rh3m-rwm3: The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 82022-05-17
CVEList
CVE-2014-2128: The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 82014-04-10

📋Vendor Advisories

2
Cisco
Multiple Vulnerabilities in Cisco ASA Software2014-04-09
Cisco
Cisco Adaptive Security Appliance SSL VPN Authentication Bypass Vulnerability2014-04-09
CVE-2014-2128 — Improper Authentication in Cisco | cvebase