Privilege escalation in Cisco Adaptive Security Appliance (ASA) - CVE-2018-15465
Published: December 19, 2018 / Updated: December 24, 2018
Cisco Adaptive Security Appliance (ASA)
Detailed vulnerability description
The vulnerability allows a remote authenticated but unprivileged attacker to gain elevated privileges on the target system.
The vulnerability exists in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software due to improper validation of user privileges when using the web management interface. A remote attacker can send specific HTTP requests via HTTPS to an affected device, retrieve files (including the running configuration) from the device or to upload and replace software images on the device with elevated privileges.