CVE-2014-3393
published 2014-10-10CVE-2014-3393: The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before…
PriorityP276medium4.3CVSS 2.0
AVNACMAuNCNIPAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.99%
78.5th percentile
The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), and 9.2 before 9.2(2.4) does not properly implement authentication, which allows remote attackers to modify RAMFS customization objects via unspecified vectors, as demonstrated by inserting XSS sequences or capturing credentials, aka Bug ID CSCup36829.
Affected
103 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Inspect the source of the Cisco Web VPN logon.html page for unexpected or injected JavaScript/HTML tags, particularly external script includes pointing to non-Cisco domains or IPs. ↗
- →Hunt for Scanbox framework JavaScript URLs injected into Cisco Web VPN portal pages; Scanbox URLs have been associated with Chinese APT activity and are used for browser/software profiling and keystroke capture. ↗
- →A Metasploit module exists for CVE-2014-3393 exploitation; monitor for exploitation attempts targeting the RAMFS customization objects on Cisco ASA devices running affected software versions (8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), 9.2 before 9.2(2.4)). ↗
- ·Exploitation requires knowledge of the targeted device's specific configuration; not all exposed ASA devices are equally trivial to exploit. ↗
- ·The attack surface also includes administrative access paths (ASDM); restricting ASDM access via ACLs and ensuring it is not Internet-facing reduces the risk of portal tampering even on patched devices. ↗
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vulncheck4.3MEDIUM
vendor_cisco7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jv7f-8qcf-9c5w: The Clientless SSL VPN portal customization framework in Cisco ASA Software 8
ghsa_unreviewed·2022-05-17
CVE-2014-3393 [MEDIUM] CWE-20 GHSA-jv7f-8qcf-9c5w: The Clientless SSL VPN portal customization framework in Cisco ASA Software 8
The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), and 9.2 before 9.2(2.4) does not properly implement authentication, which allows remote attackers to modify RAMFS customization objects via unspecified vectors, as demonstrated by inserting XSS sequences or capturing credentials, aka Bug ID CSCup36829.
VulnCheck
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Improper Authentication
vulncheck·2014·CVSS 4.3
CVE-2014-3393 [MEDIUM] Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Improper Authentication
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Improper Authentication
The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), and 9.2 before 9.2(2.4) does not properly implement authentication, which allows remote attackers to modify RAMFS customization objects via unspecified vectors, as demonstrated by inserting XSS sequences or capturing credentials, aka Bug ID CSCup36829.
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailab
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco·2014-10-08·CVSS 7.8
CVE-2014-3382 [HIGH] CWE-16 Multiple Vulnerabilities in Cisco ASA Software
Multiple Vulnerabilities in Cisco ASA Software
2015-July-08 UPDATE: Cisco PSIRT is aware of disruption to some
Cisco customers with Cisco ASA devices affected by CVE-2014-3383, the
Cisco ASA VPN Denial of Service Vulnerability that was disclosed in this
Security Advisory. Traffic causing the disruption was isolated to a
specific source IPv4 address. Cisco has engaged the provider and owner
of that device and determined that the traffic was sent with no
malicious intent. Cisco strongly recommends that customers upgrade to a
fixed Cisco ASA software release to remediate this issue.
Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities:
Cisco ASA SQL*NET Inspection Engine Denial of Service Vulnerability
Cisco ASA VPN Denial of Service Vulnerability
C
Cisco
Cisco ASA Clientless SSL VPN Portal Customization Integrity Vulnerability
vendor_cisco·2014-10-08·CVSS 4.3
CVE-2014-3393 [MEDIUM] CWE-287 Cisco ASA Clientless SSL VPN Portal Customization Integrity Vulnerability
Cisco ASA Clientless SSL VPN Portal Customization Integrity Vulnerability
A vulnerability in the Clientless SSL VPN portal customization framework could allow an
unauthenticated, remote attacker to modify the content of the Clientless SSL VPN portal, which could lead to several attacks including the stealing of credentials, cross-site scripting (XSS), and other types of web attacks on the client using the affected system.
The
vulnerability is due to a improper implementation of authentication checks in the Clientless SSL VPN portal customization framework. An attacker could exploit this
vulnerability by modifying some of the customization objects in
the RAMFS cache file system. An exploit could allow the attacker to
bypass Clientless SSL VPN authentication and modify the portal content.
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco
CVE-2014-3393 Multiple Vulnerabilities in Cisco ASA Software
CVE-2014-3393: Multiple Vulnerabilities in Cisco ASA Software
2015-July-08 UPDATE: Cisco PSIRT is aware of disruption to some Cisco customers with Cisco ASA devices affected by CVE-2014-3383, the Cisco ASA VPN Denial of Service Vulnerability that was disclosed in this Security Advisory. Traffic causing the disruption was isolated to a specific source IPv4 address. Cisco has engaged the provider and owner of that device and determined that the traffic was sent with no malicious intent. Cisco strongly recommends that customers upgrade to a fixed Cisco ASA software release to remediate this issue. Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities: Cisco ASA SQL*NET Inspection Engine Denial of Service Vulnerability Cisco ASA VPN Denial of Service Vul
No detection rules found.
No public exploits indexed.
Volexity
Virtual Private Keylogging: Cisco Web VPNs Leveraged for Access and Persistence
blogs_volexity·2015-10-07
Virtual Private Keylogging: Cisco Web VPNs Leveraged for Access and Persistence
Threat Intelligence
# Virtual Private Keylogging: Cisco Web VPNs Leveraged for Access and Persistence
October 7, 2015
Volexity
In the world of information security, there is never a dull moment. Part of the fun of working in this space is that you always get to see attackers do something new or put a new spin on something old. Last month at the CERT-EU Conference in Brussels, Belgium, Volexity gave a presentation on a recent evolution in how attackers are maintaining persistence within victim networks. The method, which involves modifying the login pages to Cisco Clientless SSL VPNs (Web VPN), is both novel and surprisingly obvious at the same time. Attackers have been able to successfully implant JavaScript code on the login pages that enables them to surreptitiously steal employee cr
Volexity
Virtual Private Keylogging: Cisco Web VPNs Leveraged for Access and Persistence
blogs_volexity·2015-10-07
Virtual Private Keylogging: Cisco Web VPNs Leveraged for Access and Persistence
Threat Intelligence
## Virtual Private Keylogging: Cisco Web VPNs Leveraged for Access and Persistence
October 7, 2015
Volexity
In the world of information security, there is never a dull moment. Part of the fun of working in this space is that you always get to see attackers do something new or put a new spin on something old. Last month at the CERT-EU Conference in Brussels, Belgium, Volexity gave a presentation on a recent evolution in how attackers are maintaining persistence within victim networks. The method, which involves modifying the login pages to Cisco Clientless SSL VPNs (Web VPN), is both novel and surprisingly obvious at the same time. Attackers have been able to successfully implant JavaScript code on the login pages that enables them to surreptitiously steal employee c
2014-10-10
Published
Exploited in the wild