A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker with administrative privileges to upload an ASDM image that contains malicious code to a device that is running Cisco ASA Software. This vulnerability is due to insufficient validation of the authenticity of an ASDM image during its installation on a device that is running Cisco ASA Software. An attacker could exploit this vulnerability by installing a crafted ASDM image on the device that is running Cisco ASA Software and then waiting for a targeted user to access that device using ASDM. A successful exploit could allow the attacker to execute arbitrary code on the machine of the targeted user with the privileges of that user on that machine. Notes: To successfully exploit this vulnerability, the attacker must have administrative privileges on the device that is running Cisco ASA Software. Potential targets are limited to users who manage the same device that is running Cisco ASA Software using ASDM. Cisco has released and will release software updates that address this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HCisco Adaptive Security Device Manager
APPCisco< 7.18.1.150Cisco Asa 5512 X
HWCiscoall versionsCisco Asa 5512 X Firmware
OSCisco< 9.18.2Cisco Asa 5515 X
HWCiscoall versionsCisco Asa 5515 X Firmware
OSCisco< 9.18.2Cisco Asa 5585 X
HWCiscoall versionsCisco Asa 5585 X Firmware
OSCisco< 9.18.2Cisco Firepower 1010
HWCiscoall versionsCisco Firepower 1120
HWCiscoall versionsCisco Firepower 1140
HWCiscoall versionsCisco Firepower 1150
HWCiscoall versionsCisco Firepower 2110
HWCiscoall versionsCisco Firepower 2120
HWCiscoall versionsCisco Firepower 2130
HWCiscoall versionsCisco Firepower 2140
HWCiscoall versionsCisco Firepower 4110
HWCiscoall versionsCisco Firepower 4112
HWCiscoall versionsCisco Firepower 4115
HWCiscoall versionsCisco Firepower 4120
HWCiscoall versionsCisco Firepower 4125
HWCiscoall versionsCisco Firepower 4140
HWCiscoall versionsCisco Firepower 4145
HWCiscoall versionsCisco Firepower 9300
HWCiscoall versionsCisco Isa 3000
HWCiscoall versionsCisco Isa 3000 Firmware
OSCisco< 9.18.2
Related vulnerabilities
Cisco FTD: statyczne konta z zakodowanymi hasłami umożliwiają nieautoryzowany dostęp
Cisco ASA — obejście uwierzytelniania Kerberos w VPN (Auth Bypass)
Path Traversal w Cisco ASA i FTD — nieautoryzowany dostęp do plików przez WebVPN/AnyConnect
Cisco FXOS/NX-OS: buffer overread w Cisco Fabric Services umożliwia DoS lub wyciek danych
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fi...