cbcvebase.
CVE-2019-1714
published 2019-05-03

CVE-2019-1714: A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect…

PriorityP354high8.6CVSS 3.1
AVNACLPRNUINSCCNIHAN
EPSS
1.98%
78.3th percentile
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to successfully establish a VPN session to an affected device. The vulnerability is due to improper credential management when using NT LAN Manager (NTLM) or basic authentication. An attacker could exploit this vulnerability by opening a VPN session to an affected device after another VPN user has successfully authenticated to the affected device via SAML SSO. A successful exploit could allow the attacker to connect to secured networks behind the affected device.

Affected

11 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance
ciscoadaptive_security_appliance_software>= 9.10 < 9.10.1.179.10.1.17
ciscoadaptive_security_appliance_software>= 9.7 < 9.8.49.8.4
ciscoadaptive_security_appliance_software>= 9.9 < 9.9.2.509.9.2.50
ciscocisco_adaptive_security_appliance_software>= unspecified < 9.8.49.8.4
ciscocisco_adaptive_security_appliance_software>= unspecified < 9.9.2.509.9.2.50
ciscocisco_adaptive_security_appliance_software>= unspecified < 9.10.1.179.10.1.17
ciscocisco_firepower_threat_defense_software>= unspecified < 6.2.3.126.2.3.12
ciscocisco_firepower_threat_defense_software>= unspecified < 6.3.0.36.3.0.3
ciscofirepower_threat_defense>= 6.2.1 < 6.2.3.126.2.3.12
ciscofirepower_threat_defense>= 6.3.0 < 6.3.0.36.3.0.3

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
nvdv3.05.8MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.