Incorrect authorization in Cisco Firewall Threat Defense (FTD) and Cisco Adaptive Security Appliance (ASA) - CVE-2022-20928
Published: November 10, 2022
Vulnerability details
The vulnerability allows a remote attacker to establish a connection as a different user.
The vulnerability exists due to a flaw in the authorization verifications during the VPN authentication flow. A remote attacker can send a specially crafted packet during a VPN authentication and establish a VPN connection with access privileges from a different user.
Affected software
Cisco Adaptive Security Appliance (ASA)
How to mitigate CVE-2022-20928
Cisco Adaptive Security Appliance (ASA) - addressed in versions 006.004(000.015), 006.006(007), 007.000(002), 007.002(000), 9.8.4.46, 009.008(004.046), 9.12.4.48, 9.12.4.50, 9.12.4.52, 9.12.4.54, 9.14.4.13, 9.14.4.14, 9.14.4.15, 9.14.4.17, 9.16.3, 9.16.3.19, 9.16.3.23, 9.16.4, 9.17.1.13, 9.17.1.15, 9.17.1.20, 009.018(001), 9.18.1, 9.18.2, 9.18.2.5, 009.019(000.099)