Insufficient verification of data authenticity in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2023-20275

 

Insufficient verification of data authenticity in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2023-20275

Published: December 5, 2023


Vulnerability identifier: #VU83885
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20275
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to impersonate other VPN users.

The vulnerability exists due to improper validation of the packet's inner source IP address after decryption in the AnyConnect SSL VPN feature. A remote user can send specially crafted packets through the tunnel, impersonate another VPN user's IP address and receive return packets.


Affected software

Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)

How to mitigate CVE-2023-20275

Install updates from vendor's website.


External References

Related Security Bulletins