Cisco Adaptive Security Appliance Software Version
An attacker could exploit this vulnerability.
Cisco adaptive security appliance software version. The vulnerability is due to insufficient csrf protections for the web based management interface on an affected device. Release notes for the cisco asa device package software version 1 3 12 for aci 17 may 2019. Xml examples for the cisco asa device package software version 1 3 12 for aci. A vulnerability in the web based management interface of cisco adaptive security appliance asa software could allow an unauthenticated remote attacker to conduct a cross site request forgery csrf attack on an affected system.
It delivers enterprise class firewall capabilities for asa devices in an array of form factors standalone appliances blades and virtual appliances for any distributed network environment. Release notes for the cisco asa device package software version 1 3 11 for aci 02 nov 2018. Release notes for the cisco asa device package software version 1 3 10 for aci 28 aug 2018. The vulnerability is due to improper validation of user privileges when using the web management interface.
A vulnerability in the authorization subsystem of cisco adaptive security appliance asa software could allow an authenticated but unprivileged levels 0 and 1 remote attacker to perform privileged actions by using the web management interface. Cisco adaptive security appliance asa software. Cisco adaptive security appliance software and firepower threat defense software web services read only path traversal vulnerability 27 aug 2020 cisco ios xe software and cisco asa 5500 x series adaptive security appliance ipsec denial of service vulnerability 25 aug 2020. Cisco adaptive security appliance asa software is the core operating system for the cisco asa family.