Security restrictions bypass in Cisco Adaptive Security Appliance (ASA) - CVE-2018-15398

 

Security restrictions bypass in Cisco Adaptive Security Appliance (ASA) - CVE-2018-15398

Published: October 14, 2018


Vulnerability identifier: #VU15360
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15398
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to bypass security restrictions on the target system.

The weakness exists in the per-user-override feature due to errors when the affected software constructs and applies per-user-override rules. A remote attacker can connect to a network through an affected device that has a vulnerable configuration and access resources that are behind the affected device and would typically be protected by the interface ACL.

Affected software

Cisco Adaptive Security Appliance (ASA)

How to mitigate CVE-2018-15398

Install update from vendor's website.


External References

Related Security Bulletins