cbcvebase.
CVE-2023-20269
published 2023-09-06

CVE-2023-20269: A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could…

PriorityP195critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2023-10-04
Exploited in the wild
EPSS
21.58%
97.3th percentile
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user. This vulnerability is due to improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. An attacker could exploit this vulnerability by specifying a default connection profile/tunnel group while conducting a brute force attack or while establishing a clientless SSL VPN session using valid credentials. A successful exploit could allow the attacker to achieve one or both of the following: Identify valid credentials that could then be used to establish an unauthorized remote access VPN session. Establish a clientless SSL VPN session (only when running Cisco ASA Software Release 9.16 or earlier). Notes: Establishing a client-based remote access VPN tunnel is not possible as these default connection profiles/tunnel groups do not and cannot have an IP address pool configured. This vulnerability does not allow an attacker to bypass authentication. To successfully establish a remote access VPN session, valid credentials are required, including a valid second factor if multi-factor authentication (MFA) is configured. Cisco will release software updates that address this vulnerability. There are workarounds that address this vulnerability.

Affected

493 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software

Detection & IOCsextracted from sources · hover to see the quote

filenameakira_readme.txt
commandpowershell.exe -Command "Get-WmiObject Win32_Shadowcopy | Remove-WmiObject"
processPSEXESVC.exe
command"C:\Program Files\WinRAR\WinRAR.exe" a -ep1 -scul -r0 -iext -imon1 -- . "[REDACTED]\Company\[REDACTED]" [REDACTED]\Company\HR "[REDACTED]\Company\Human Resources Management - HR"
  • CVE-2023-20269 exploitation targets the web services interface (AAA functions) of Cisco ASA/FTD; detect by monitoring for high-volume authentication requests to the VPN web services interface with no rate-limiting or lockout, especially against the default connection profile/tunnel group.
  • Exploitation requires SSL VPN enabled on at least one interface OR IKEv2 VPN enabled on at least one interface, combined with at least one LOCAL database user with a password or HTTPS management auth pointing to a valid AAA server — use these as detection pre-conditions.
  • Attackers exploiting CVE-2023-20269 specify a default connection profile/tunnel group (DefaultADMINGroup or DefaultL2LGroup) during brute force or session establishment — monitor for VPN tunnel attempts using these default group names.
  • Post-exploitation: monitor for creation of new administrative domain accounts named 'itadm' as a persistence indicator following Cisco VPN compromise.
  • Post-exploitation: detect LSASS MiniDump creation via comsvcs.dll as a credential-harvesting follow-on after initial access through CVE-2023-20269.
  • Post-exploitation: detect copying of NTDS.dit and SYSTEM registry hive from domain controllers as a follow-on credential-extraction technique after initial VPN access.
  • ·Brute-force exploitation of CVE-2023-20269 only works when the device has at least one LOCAL database user with a password configured, or HTTPS management authentication points to a valid AAA server — devices without these configurations are not vulnerable to the brute-force vector.
  • ·Clientless SSL VPN session establishment via CVE-2023-20269 is only possible on Cisco ASA Software Release 9.16 or earlier — later releases are not affected by this specific impact.
  • ·Establishing a client-based remote access VPN tunnel is NOT possible via this vulnerability, as default connection profiles/tunnel groups cannot have an IP address pool configured — scope detection to clientless SSL VPN and brute-force activity only.
  • ·MFA mitigates the risk of account takeover even if credentials are successfully brute-forced — CVE-2023-20269 does not allow bypassing MFA.

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vulncheck5.0MEDIUM
cisa9.1CRITICAL
vendor_cisco5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.