CVE-2019-1714
published 2019-05-03CVE-2019-1714: A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect…
PriorityP354high8.6CVSS 3.1
AVNACLPRNUINSCCNIHAN
EPSS
1.98%
78.3th percentile
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to successfully establish a VPN session to an affected device. The vulnerability is due to improper credential management when using NT LAN Manager (NTLM) or basic authentication. An attacker could exploit this vulnerability by opening a VPN session to an affected device after another VPN user has successfully authenticated to the affected device via SAML SSO. A successful exploit could allow the attacker to connect to secured networks behind the affected device.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | >= 9.10 < 9.10.1.17 | 9.10.1.17 |
| cisco | adaptive_security_appliance_software | >= 9.7 < 9.8.4 | 9.8.4 |
| cisco | adaptive_security_appliance_software | >= 9.9 < 9.9.2.50 | 9.9.2.50 |
| cisco | cisco_adaptive_security_appliance_software | >= unspecified < 9.8.4 | 9.8.4 |
| cisco | cisco_adaptive_security_appliance_software | >= unspecified < 9.9.2.50 | 9.9.2.50 |
| cisco | cisco_adaptive_security_appliance_software | >= unspecified < 9.10.1.17 | 9.10.1.17 |
| cisco | cisco_firepower_threat_defense_software | >= unspecified < 6.2.3.12 | 6.2.3.12 |
| cisco | cisco_firepower_threat_defense_software | >= unspecified < 6.3.0.3 | 6.3.0.3 |
| cisco | firepower_threat_defense | >= 6.2.1 < 6.2.3.12 | 6.2.3.12 |
| cisco | firepower_threat_defense | >= 6.3.0 < 6.3.0.3 | 6.3.0.3 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
nvdv3.05.8MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software VPN SAML Authentication Bypass Vulnerability
vendor_cisco·2019-05-01·CVSS 5.8
CVE-2019-1714 [MEDIUM] CWE-255 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software VPN SAML Authentication Bypass Vulnerability
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software VPN SAML Authentication Bypass Vulnerability
A vulnerability in the implementation of Security Assertion Markup
Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and
AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA)
Software and Cisco Firepower Threat Defense (FTD) Software could allow
an unauthenticated, remote attacker to successfully establish a VPN
session to an affected device.
The vulnerability is due to
improper credential management when using NT LAN Manager (NTLM) or basic
authentication. An attacker could exploit this vulnerability by opening
a VPN session to an affected device after another VPN user has
successfully authenticated to the affected device
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software VPN SAML Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1714 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software VPN SAML Authentication Bypass Vulnerability
CVE-2019-1714: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software VPN SAML Authentication Bypass Vulnerability
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to successfully establish a VPN session to an affected device. The vulnerability is due to improper credential management when using NT LAN Manager (NTLM) or basic authentication. An attacker could exploit this vulnerability by opening a VPN session to an affected device after another VPN user has successfully authenticated to the aff
GHSA
GHSA-c2pv-f87v-p3wc: A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2
ghsa_unreviewed·2022-05-24
CVE-2019-1714 [HIGH] GHSA-c2pv-f87v-p3wc: A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to successfully establish a VPN session to an affected device. The vulnerability is due to improper credential management when using NT LAN Manager (NTLM) or basic authentication. An attacker could exploit this vulnerability by opening a VPN session to an affected device after another VPN user has successfully authenticated to the affected device via SAML SSO. A successful exploit could allow the attacker to connect to secured networks behind the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-05-03
Published