CVE-2021-1585
published 2021-07-08CVE-2021-1585: A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a…
PriorityP263high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
19.96%
97.1th percentile
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for specific code exchanged between the ASDM and the Launcher. An attacker could exploit this vulnerability by leveraging a man-in-the-middle position on the network to intercept the traffic between the Launcher and the ASDM and then inject arbitrary code. A successful exploit could allow the attacker to execute arbitrary code on the user's operating system with the level of privileges assigned to the ASDM Launcher. A successful exploit may require the attacker to perform a social engineering attack to persuade the user to initiate communication from the Launcher to the ASDM.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_device_manager | < 7.18.1.152 | 7.18.1.152 |
| cisco | adaptive_security_device_manager | — | — |
| cisco | cisco_adaptive_security_appliance_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit requires attacker to hold a man-in-the-middle position on the network to intercept traffic between the ASDM Launcher and the ASDM, then inject arbitrary code — monitor for unexpected interception or modification of ASDM Launcher communications. ↗
- →The vulnerability stems from missing signature verification on code exchanged between ASDM and the Launcher — inspect ASDM Launcher update/code-exchange traffic for unsigned or anomalously signed payloads. ↗
- →Successful exploitation results in arbitrary code execution at the privilege level of the ASDM Launcher process — alert on unexpected child processes or privilege escalation events spawned from the ASDM Launcher. ↗
- →Attack may be preceded by a social engineering phase to get the user to initiate a Launcher-to-ASDM connection — correlate user-reported phishing/social engineering attempts with subsequent ASDM Launcher network activity. ↗
- ·No workarounds exist; the only remediation is applying Cisco's released software updates for ASDM. ↗
- ·Tracked under Cisco Bug ID CSCvw79912; use this identifier when querying Cisco's bug tracker or PSIRT for patch status. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Device Manager Remote Code Execution Vulnerability
vendor_cisco·2021-07-07·CVSS 7.5
CVE-2021-1585 [HIGH] CWE-94 Cisco Adaptive Security Device Manager Remote Code Execution Vulnerability
Cisco Adaptive Security Device Manager Remote Code Execution Vulnerability
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system.
This vulnerability is due to a lack of proper signature verification for specific code exchanged between the ASDM and the Launcher. An attacker could exploit this vulnerability by leveraging a man-in-the-middle position on the network to intercept the traffic between the Launcher and the ASDM and then inject arbitrary code. A successful exploit could allow the attacker to execute arbitrary code on the user's operating system with the level of privileges assigned to the ASDM Launcher. A successful exploit may require the attacker to per
Cisco
Cisco Adaptive Security Device Manager Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1585 Cisco Adaptive Security Device Manager Remote Code Execution Vulnerability
CVE-2021-1585: Cisco Adaptive Security Device Manager Remote Code Execution Vulnerability
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for specific code exchanged between the ASDM and the Launcher. An attacker could exploit this vulnerability by leveraging a man-in-the-middle position on the network to intercept the traffic between the Launcher and the ASDM and then inject arbitrary code. A successful exploit could allow the attacker to execute arbitrary code on the user's operating system with the level of privileges assigned to the ASDM Launcher. A successful exploit may require the at
GHSA
GHSA-3fc6-gf75-vvc3: A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary cod
ghsa_unreviewed·2022-05-24
CVE-2021-1585 [HIGH] CWE-94 GHSA-3fc6-gf75-vvc3: A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary cod
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for specific code exchanged between the ASDM and the Launcher. An attacker could exploit this vulnerability by leveraging a man-in-the-middle position on the network to intercept the traffic between the Launcher and the ASDM and then inject arbitrary code. A successful exploit could allow the attacker to execute arbitrary code on the user's operating system with the level of privileges assigned to the ASDM Launcher. A successful exploit may require the attacker to perform a social engineering attack to persuade the user to initiate communicati
No detection rules found.
No public exploits indexed.
arXiv
An Explainable Ensemble-based Intrusion Detection System for Software-Defined Vehicle Ad-hoc Networks
arxiv_fulltext·2024-10-11
An Explainable Ensemble-based Intrusion Detection System for Software-Defined Vehicle Ad-hoc Networks
1
.001
An Explainable Ensemble-based IDS for SDVN
Ahsan et al.
[mode = title]An Explainable Ensemble-based Intrusion Detection System for Software-Defined Vehicle Ad-hoc Networks
[1]Shakil Ibne Ahsan[orcid=0009-0001-9380-0079]
[1]
[email protected]
Conceptualisation of this study, Methodology, Software
[1]organization=University of the West of England, addressline=Coldharbour Lane,
city=Bristol,
postcode=BS16 1QY,
country=UK
[2]organization=Intel Labs, addressline=Intel Corporation,
city=California,
country=USA
[1]Phil Legg[orcid=0000-0003-3460-5609]
[2]S M Iftekharul Alam
Data curation, Writing - Original draft preparation
[cor1]Corresponding author
## Abstract
Intrusion Detection Systems (IDS) are widely employed to detect and mitigate external network security events. Veh
Bugzilla
CVE-2016-10228 glibc: iconv program can hang when invoked with the -c option
bugzilla·2017-03-02·CVSS 5.9
CVE-2016-10228 [MEDIUM] CVE-2016-10228 glibc: iconv program can hang when invoked with the -c option
CVE-2016-10228 glibc: iconv program can hang when invoked with the -c option
A vulnerability was found in the iconv program provided by glibc when it's invoked with the -c option. It can enter an infinite loop while parsing an invalid multi-byte sequence.
References:
http://seclists.org/oss-sec/2017/q1/538
Upstream bug:
https://sourceware.org/bugzilla/show_bug.cgi?id=19519
Discussion:
Created glibc tracking bugs for this issue:
Affects: fedora-all [bug 1428292]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2021:1585 https://access.redhat.com/errata/RHSA-2021:1585
https://github.com/jbaines-r7/staystaystayhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asdm-rce-gqjShXWhttps://www.rapid7.com/blog/post/2022/08/11/rapid7-discovered-vulnerabilities-in-cisco-asa-asdm-and-firepower-services-software/https://github.com/jbaines-r7/staystaystayhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asdm-rce-gqjShXWhttps://www.rapid7.com/blog/post/2022/08/11/rapid7-discovered-vulnerabilities-in-cisco-asa-asdm-and-firepower-services-software/
2021-07-08
Published