#VU27688 Improper Authentication in Cisco Adaptive Security Appliance (ASA) - CVE-2020-3125
Published: May 11, 2020
Cisco Adaptive Security Appliance (ASA)
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists in the Kerberos authentication feature due to insufficient identity verification of the KDC when a successful authentication response is received. A remote attacker can spoof the KDC server response to the ASA device and bypass Kerberos authentication.