Information disclosure in Cisco Adaptive Security Appliance (ASA) - CVE-2014-3398
Published: October 6, 2014 / Updated: February 27, 2017
Cisco Adaptive Security Appliance (ASA)
Detailed vulnerability description
The vulnerability allows a remote unauthenticated attacker to obtain potentially sensitive information.
The vulnerability exists due to excessive information output in Cisco SSL VPN feature. A remote unauthenticated attacker can obtain version of Cisco ASA software by directly requesting "/CSCOSSLC/config-auth" URL.
Successful exploitation of the vulnerability may allow an attacker to obtain version number of Cisco ASA software.