CVE-2015-0760
published 2015-06-04CVE-2015-0760: The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated users to bypass XAUTH authentication…
PriorityP424medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.03%
78.8th percentile
The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated users to bypass XAUTH authentication via crafted IKEv1 packets, aka Bug ID CSCus47259.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | >= 7.0 < 8.2.2.13 | 8.2.2.13 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance XAUTH Bypass Vulnerability
vendor_cisco·2015-06-02·CVSS 4.0
CVE-2015-0760 [MEDIUM] CWE-20 Cisco Adaptive Security Appliance XAUTH Bypass Vulnerability
Cisco Adaptive Security Appliance XAUTH Bypass Vulnerability
A vulnerability in Internet Key Exchange (IKE) version 1 (v1) code of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to bypass Extended Authentication (XAUTH) and successfully log in via IPsec remote VPN.
The vulnerability is due to improper implementation of the logic of the XAUTH code. An attacker could exploit this vulnerability by sending crafted IKEv1 packets to the affected system. An exploit could allow the attacker to bypass authentication and access the network via remote VPN.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement decreases the lik
GHSA
GHSA-99qq-rjrp-5v3c: The IKEv1 implementation in Cisco ASA Software 7
ghsa_unreviewed·2022-05-17
CVE-2015-0760 [MEDIUM] CWE-20 GHSA-99qq-rjrp-5v3c: The IKEv1 implementation in Cisco ASA Software 7
The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated users to bypass XAUTH authentication via crafted IKEv1 packets, aka Bug ID CSCus47259.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-04
Published