CVE-2017-6752
published 2017-08-07CVE-2017-6752: A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2) could allow an unauthenticated, remote attacker to…
PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.23%
80.9th percentile
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2) could allow an unauthenticated, remote attacker to determine valid usernames. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to the interaction between Lightweight Directory Access Protocol (LDAP) and SSL Connection Profile when they are configured together. An attacker could exploit the vulnerability by performing a username enumeration attack to the IP address of the device. An exploit could allow the attacker to determine valid usernames. Cisco Bug IDs: CSCvd47888.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_username_enumeration | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wvc6-xr2j-qjmh: A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9
ghsa_unreviewed·2022-05-13
CVE-2017-6752 [HIGH] CWE-200 GHSA-wvc6-xr2j-qjmh: A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2) could allow an unauthenticated, remote attacker to determine valid usernames. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to the interaction between Lightweight Directory Access Protocol (LDAP) and SSL Connection Profile when they are configured together. An attacker could exploit the vulnerability by performing a username enumeration attack to the IP address of the device. An exploit could allow the attacker to determine valid usernames. Cisco Bug IDs: CSCvd47888.
Cisco
Cisco Adaptive Security Appliance Username Enumeration Information Disclosure Vulnerability
vendor_cisco·2017-08-02·CVSS 5.3
CVE-2017-6752 [MEDIUM] CWE-200 Cisco Adaptive Security Appliance Username Enumeration Information Disclosure Vulnerability
Cisco Adaptive Security Appliance Username Enumeration Information Disclosure Vulnerability
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to determine valid usernames. The attacker could use this information to conduct additional reconnaissance attacks.
The vulnerability is due to the interaction between Lightweight Directory Access Protocol (LDAP) and SSL Connection Profile when they are configured together. An attacker could exploit the vulnerability by performing a username enumeration attack to the IP address of the device. An exploit could allow the attacker to determine valid usernames.
There are workarounds that address this vulnerability.
This advisory is available at the following link:
https
Cisco
Cisco Adaptive Security Appliance Username Enumeration Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6752 Cisco Adaptive Security Appliance Username Enumeration Information Disclosure Vulnerability
CVE-2017-6752: Cisco Adaptive Security Appliance Username Enumeration Information Disclosure Vulnerability
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to determine valid usernames. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to the interaction between Lightweight Directory Access Protocol (LDAP) and SSL Connection Profile when they are configured together. An attacker could exploit the vulnerability by performing a username enumeration attack to the IP address of the device. An exploit could allow the attacker to determine valid usernames. There are
CVSS: 3.0
CWE: CWE-200, CWE-200
Bug IDs: CSCvd47888
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/100113http://www.securitytracker.com/id/1039057https://quickview.cloudapps.cisco.com/quickview/bug/CSCvd47888https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170802-asa2http://www.securityfocus.com/bid/100113http://www.securitytracker.com/id/1039057https://quickview.cloudapps.cisco.com/quickview/bug/CSCvd47888https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170802-asa2
2017-08-07
Published