CVE-2015-6344
published 2015-10-30CVE-2015-6344: The web-based GUI in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security 9.3(4.1.11) allows remote authenticated users to bypass intended access…
PriorityP418medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.37%
68.8th percentile
The web-based GUI in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security 9.3(4.1.11) allows remote authenticated users to bypass intended access restrictions and obtain sensitive user information via an unspecified HTTP request, aka Bug ID CSCuv74105.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_web | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h58g-f77x-j9p5: The web-based GUI in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security 9
ghsa_unreviewed·2022-05-17
CVE-2015-6344 [MEDIUM] CWE-200 GHSA-h58g-f77x-j9p5: The web-based GUI in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security 9
The web-based GUI in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security 9.3(4.1.11) allows remote authenticated users to bypass intended access restrictions and obtain sensitive user information via an unspecified HTTP request, aka Bug ID CSCuv74105.
Cisco
Cisco ASA CX Context-Aware Security Web GUI Unauthorized Access Vulnerability
vendor_cisco·2015-10-27·CVSS 4.0
CVE-2015-6344 [MEDIUM] CWE-200 Cisco ASA CX Context-Aware Security Web GUI Unauthorized Access Vulnerability
Cisco ASA CX Context-Aware Security Web GUI Unauthorized Access Vulnerability
A vulnerability in the web-based GUI of Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security could allow an authenticated, remote attacker to enumerate users and read user information without belonging to a role that allows those operations.
The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by sending an HTTP request to a specific URL.
Cisco has not released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151027-cas
Cisco
Cisco ASA CX Context-Aware Security Web GUI Unauthorized Access Vulnerability
vendor_cisco
CVE-2015-6344 Cisco ASA CX Context-Aware Security Web GUI Unauthorized Access Vulnerability
CVE-2015-6344: Cisco ASA CX Context-Aware Security Web GUI Unauthorized Access Vulnerability
A vulnerability in the web-based GUI of Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security could allow an authenticated, remote attacker to enumerate users and read user information without belonging to a role that allows those operations. The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by sending an HTTP request to a specific URL. Cisco has not released software updates that address this vulnerability. There are no
CWE: CWE-200, CWE-200
Bug IDs: CSCuv74105
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-10-30
Published