Authentication bypass using an alternate path or channel in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2023-20269

 

Authentication bypass using an alternate path or channel in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2023-20269

Published: September 7, 2023 / Updated: September 8, 2023


Vulnerability identifier: #VU80521
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20269
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. A remote user can perform a brute-force attack and establish a clientless SSL VPN session with an unauthorized user.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)

How to mitigate CVE-2023-20269

Install updates from vendor's website.

Cisco Adaptive Security Appliance (ASA) - update to 9.16.4.38
Cisco Firewall Threat Defense (FTD) - update to 9.16.4.38

External References

Related Security Bulletins