CVE-2020-3125
published 2020-05-06CVE-2020-3125: A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.36%
81.9th percentile
A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) and bypass authentication on an affected device that is configured to perform Kerberos authentication for VPN or local device access. The vulnerability is due to insufficient identity verification of the KDC when a successful authentication response is received. An attacker could exploit this vulnerability by spoofing the KDC server response to the ASA device. This malicious response would not have been authenticated by the KDC. A successful attack could allow an attacker to bypass Kerberos authentication.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | >= 9.10 < 9.10.1.37 | 9.10.1.37 |
| cisco | adaptive_security_appliance_software | >= 9.12 < 9.12.3.2 | 9.12.3.2 |
| cisco | adaptive_security_appliance_software | >= 9.13 < 9.13.1.7 | 9.13.1.7 |
| cisco | adaptive_security_appliance_software | >= 9.8 < 9.8.4.15 | 9.8.4.15 |
| cisco | adaptive_security_appliance_software | >= 9.9 < 9.9.2.66 | 9.9.2.66 |
| cisco | asa_5505_firmware | — | — |
| cisco | asa_5510_firmware | — | — |
| cisco | asa_5512-x_firmware | — | — |
| cisco | asa_5515-x_firmware | — | — |
| cisco | asa_5520_firmware | — | — |
| cisco | asa_5525-x_firmware | — | — |
| cisco | asa_5540_firmware | — | — |
| cisco | asa_5545-x_firmware | — | — |
| cisco | asa_5550_firmware | — | — |
| cisco | asa_5555-x_firmware | — | — |
| cisco | asa_5580_firmware | — | — |
| cisco | asa_5585-x_firmware | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthenticated Kerberos authentication bypass attempts against Cisco ASA by monitoring for successful Kerberos authentication responses that were not validated/authenticated by the KDC — specifically spoofed KDC server responses to the ASA device. ↗
- →Focus detection on Cisco ASA devices configured for Kerberos authentication for VPN or local device access, as these are the affected attack surfaces. ↗
- ·Software upgrade alone is insufficient — configuration changes after the software upgrade are also required to fully remediate this vulnerability. ↗
- ·There are no workarounds available for this vulnerability; patching and reconfiguration are the only mitigations. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9x68-6g6c-vj48: A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote atta
ghsa_unreviewed·2022-05-24
CVE-2020-3125 [MEDIUM] CWE-287 GHSA-9x68-6g6c-vj48: A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote atta
A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) and bypass authentication on an affected device that is configured to perform Kerberos authentication for VPN or local device access. The vulnerability is due to insufficient identity verification of the KDC when a successful authentication response is received. An attacker could exploit this vulnerability by spoofing the KDC server response to the ASA device. This malicious response would not have been authenticated by the KDC. A successful attack could allow an attacker to bypass Kerberos authentication.
Cisco
Cisco Adaptive Security Appliance Software Kerberos Authentication Bypass Vulnerability
vendor_cisco·2020-05-06·CVSS 8.1
CVE-2020-3125 [HIGH] CWE-287 Cisco Adaptive Security Appliance Software Kerberos Authentication Bypass Vulnerability
Cisco Adaptive Security Appliance Software Kerberos Authentication Bypass Vulnerability
A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) and bypass authentication on an affected device that is configured to perform Kerberos authentication for VPN or local device access.
The vulnerability is due to insufficient identity verification of the KDC when a successful authentication response is received. An attacker could exploit this vulnerability by spoofing the KDC server response to the ASA device. This malicious response would not have been authenticated by the KDC. A successful attack could allow an attacker to bypass Kerberos a
No detection rules found.
No public exploits indexed.
Tenable
Cisco Patches Multiple Flaws in Adaptive Security Appliance and Firepower Threat Defense (CVE-2020-3187)
blogs_tenable·2020-05-07·CVSS 9.1
[CRITICAL] Cisco Patches Multiple Flaws in Adaptive Security Appliance and Firepower Threat Defense (CVE-2020-3187)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2020-28491 jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception
bugzilla·2021-02-18·CVSS 7.5
CVE-2020-28491 [HIGH] CVE-2020-28491 jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception
CVE-2020-28491 jackson-dataformat-cbor: Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.
https://github.com/FasterXML/jackson-dataformats-binary/commit/de072d314af8f5f269c8abec6930652af67bc8e6
https://github.com/FasterXML/jackson-dataformats-binary/issues/186
https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONDATAFORMAT-1047329
Discussion:
This issue has been addressed in the following products:
vertx 4.1.2
Via RHSA-2021:3125 https://access.redhat.com/errata/RHSA-2021:3125
---
This bug is now closed. Further updates for in
2020-05-06
Published