Insufficient verification of data authenticity in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2023-20275
Published: December 5, 2023
Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
Cisco Systems, Inc
Description
The vulnerability allows a remote user to impersonate other VPN users.
The vulnerability exists due to improper validation of the packet's inner source IP address after decryption in the AnyConnect SSL VPN feature. A remote user can send specially crafted packets through the tunnel, impersonate another VPN user's IP address and receive return packets.