CVE-2018-15465
published 2018-12-24CVE-2018-15465: A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and…
PriorityP352high8.1CVSS 3.0
AVNACLPRLUINSUCHIHAN
EPSS
2.36%
81.9th percentile
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using the web management interface. An attacker could exploit this vulnerability by sending specific HTTP requests via HTTPS to an affected device as an unprivileged user. An exploit could allow the attacker to retrieve files (including the running configuration) from the device or to upload and replace software images on the device.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | < 9.4.4.29 | 9.4.4.29 |
| cisco | adaptive_security_appliance_software | >= 9.10 < 9.10.1.7 | 9.10.1.7 |
| cisco | adaptive_security_appliance_software | >= 9.5 < 9.6.4.20 | 9.6.4.20 |
| cisco | adaptive_security_appliance_software | >= 9.7 < 9.8.3.18 | 9.8.3.18 |
| cisco | adaptive_security_appliance_software | >= 9.9 < 9.9.2.36 | 9.9.2.36 |
| cisco | cisco_adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
vendor_cisco8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance Software Privilege Escalation Vulnerability
vendor_cisco·2018-12-19·CVSS 8.1
CVE-2018-15465 [HIGH] CWE-285 Cisco Adaptive Security Appliance Software Privilege Escalation Vulnerability
Cisco Adaptive Security Appliance Software Privilege Escalation Vulnerability
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface.
The vulnerability is due to improper validation of user privileges when using the web management interface. An attacker could exploit this vulnerability by sending specific HTTP requests via HTTPS to an affected device as an unprivileged user. An exploit could allow the attacker to retrieve files (including the running configuration) from the device or to upload and replace software images on the device.
Cisco has released software updates that address this vulnerabil
Cisco
Cisco Adaptive Security Appliance Software Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-15465 Cisco Adaptive Security Appliance Software Privilege Escalation Vulnerability
CVE-2018-15465: Cisco Adaptive Security Appliance Software Privilege Escalation Vulnerability
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using the web management interface. An attacker could exploit this vulnerability by sending specific HTTP requests via HTTPS to an affected device as an unprivileged user. An exploit could allow the attacker to retrieve files (including the running configuration) from the device or to upload and replace software images on the device. Cisco has released software updates that address
GHSA
GHSA-wccp-c983-j22q: A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (lev
ghsa_unreviewed·2022-05-13
CVE-2018-15465 [HIGH] CWE-285 GHSA-wccp-c983-j22q: A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (lev
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using the web management interface. An attacker could exploit this vulnerability by sending specific HTTP requests via HTTPS to an affected device as an unprivileged user. An exploit could allow the attacker to retrieve files (including the running configuration) from the device or to upload and replace software images on the device.
No detection rules found.
No public exploits indexed.
Tenable
Privilege Escalation Flaw Discovered in the Cisco Adaptive Security Appliance
blogs_tenable·2018-12-19
Privilege Escalation Flaw Discovered in the Cisco Adaptive Security Appliance
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Privilege Escalation Flaw Discovered in the Cisco Adaptive Security Appliance
blogs_tenable·2018-12-19·CVSS 8.1
[HIGH] Privilege Escalation Flaw Discovered in the Cisco Adaptive Security Appliance
Blog / Research
Subscribe
# Privilege Escalation Flaw Discovered in the Cisco Adaptive Security Appliance
Ryan Seguin
December 19, 2018
3 Min Read
Tenable has discovered a privilege escalation flaw in the Cisco Adaptive Security Appliance that allows low-level users to run higher-level commands when certain configuration settings are set.
- What you need to know: An authenticated remote unprivileged user can change or download the running configuration or replace the appliance firmware where they shouldn’t.
- What’s the attack vector? HTTP Requests
- What’s the business impact? Attackers could read or write files on the system, overwrite firmware and create new users.
- What’s the solution? Update to the latest version of Cisco IOS.
### Background
Tenable has discovered privilege e
http://www.securityfocus.com/bid/106256https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181219-asa-priveschttps://www.tenable.com/security/research/tra-2018-46http://www.securityfocus.com/bid/106256https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181219-asa-priveschttps://www.tenable.com/security/research/tra-2018-46
2018-12-24
Published