A Privilege Escalation vulnerability discovered in Cisco ASA allows an lowest privilege user to overwrite the system’s firmware, full configuration file, and to create new users.
The vulnerability was identified by Tenable, tracked as CVE-2018-15465, allows a remote attacker to perform privileged actions in the web interface.
To exploit this vulnerability the attacker “requires the HTTP interface for IOS to be enabled, and the “aaa” authentication scheme needs to be set, which is not part of the ASAv default configuration.”
The vulnerability is due to the improper validation of user management in the webmanagement, an attacker could exploit this vulnerability by sending a crafted HTTP requests through HTTPS to the affected as an unprivileged user.
An attacker could exploit the vulnerability to retrive files from the device or to upload and replace software images on the device.
The vulnerability affects all the Cisco ASA Software running with web management access enabled.
Now Cisco has released an advisory and patches, enabling command authorization prevents the exploitation of this vulnerability.
Cisco recommends “Administrators who use the Adaptive Security Device Manager (ASDM) to manage the ASA are advised to enable command authorization by using the ASDM because doing so will allow the ASDM to push predefined command sets for different privilege to the ASA.”
Cisco Releases Security Updates that Covers 16 Vulnerabilities that had Critical and High Impact
Cisco Released Security Updates for Multiple Vulnerabilities that Affected Cisco Products
Cisco Released Critical Security Updates for Vulnerabilities that Affected Cisco Products
Researchers have discovered a critical flaw in Active Directory’s NTLMv1 mitigation strategy, where misconfigured on-premises…
Amazon Web Services (AWS) has issued a critical security advisory highlighting vulnerabilities in specific versions…
Rockstar2FA is a PaaS kit that mimics the legitimate credential-request behavior of cloud/SaaS platforms. Phishing…
A Russian software developer, aided by the National Technology Initiative, has introduced a groundbreaking AI…
A serious security flaw has been identified in Ivanti Connect Secure, designated as CVE-2025-0282, which enables…
Let’s Encrypt has announced plans to introduce six-day certificate options and support for IP address…