#VU69201 Incorrect authorization in Cisco Adaptive Security Appliance (ASA) and Cisco Firewall Threat Defense (FTD) - CVE-2022-20928
Published: November 10, 2022
Cisco Adaptive Security Appliance (ASA)
Cisco Firewall Threat Defense (FTD)
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to establish a connection as a different user.
The vulnerability exists due to a flaw in the authorization verifications during the VPN authentication flow. A remote attacker can send a specially crafted packet during a VPN authentication and establish a VPN connection with access privileges from a different user.