cbcvebase.
CVE-2021-1585
published 2021-07-08

CVE-2021-1585: A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a…

PriorityP263high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
19.96%
97.1th percentile
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for specific code exchanged between the ASDM and the Launcher. An attacker could exploit this vulnerability by leveraging a man-in-the-middle position on the network to intercept the traffic between the Launcher and the ASDM and then inject arbitrary code. A successful exploit could allow the attacker to execute arbitrary code on the user's operating system with the level of privileges assigned to the ASDM Launcher. A successful exploit may require the attacker to perform a social engineering attack to persuade the user to initiate communication from the Launcher to the ASDM.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_device_manager< 7.18.1.1527.18.1.152
ciscoadaptive_security_device_manager
ciscocisco_adaptive_security_appliance_software

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit requires attacker to hold a man-in-the-middle position on the network to intercept traffic between the ASDM Launcher and the ASDM, then inject arbitrary code — monitor for unexpected interception or modification of ASDM Launcher communications.
  • The vulnerability stems from missing signature verification on code exchanged between ASDM and the Launcher — inspect ASDM Launcher update/code-exchange traffic for unsigned or anomalously signed payloads.
  • Successful exploitation results in arbitrary code execution at the privilege level of the ASDM Launcher process — alert on unexpected child processes or privilege escalation events spawned from the ASDM Launcher.
  • Attack may be preceded by a social engineering phase to get the user to initiate a Launcher-to-ASDM connection — correlate user-reported phishing/social engineering attempts with subsequent ASDM Launcher network activity.
  • ·No workarounds exist; the only remediation is applying Cisco's released software updates for ASDM.
  • ·Tracked under Cisco Bug ID CSCvw79912; use this identifier when querying Cisco's bug tracker or PSIRT for patch status.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.