Release date:
Updated on:
Affected Systems:
Cisco Adaptive Security Appliance 9.x
Cisco Adaptive Security Appliance 8.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66748
CVE (CAN) ID: CVE-2014-2127
The Cisco ASA 5500 Series Adaptive Security Device is a modular platform for providing security and VPN services. It provides firewall, IPS, anti-X, and VPN services.
Cisco Adaptive Security Appliance (ASA) Software Versions earlier than 8.2 (5.48), 8.3 (2.40), 8.4 (7.9), and 8.6 (1.13) the management session information is not correctly handled during permission verification in ssl vpn portal connections in earlier versions and versions 9.1 (4.3, this vulnerability allows authenticated remote users to obtain permissions by establishing a non-client ssl vpn session and entering a special URL.
<* Source: Jonathan clodius
Laura Guay
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.cisco.com/go/psirt
Http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-asa