Tracker / CVE-2018-15465
CVE-2018-15465
High 8.1
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using the web management interface. An attacker could exploit this vulnerability by sending specific HTTP requests via HTTPS to an affected device as an unprivileged user. An exploit could allow the attacker to retrieve files (including the running configuration) from the device or to upload and replace software images on the device.
Affected products and versions
| cisco | adaptive_security_appliance_software · … → 9.4.4.29 |
|---|---|
| cisco | adaptive_security_appliance_software · 9.10 → 9.10.1.7 |
| cisco | adaptive_security_appliance_software · 9.5 → 9.6.4.20 |
| cisco | adaptive_security_appliance_software · 9.7 → 9.8.3.18 |
| cisco | adaptive_security_appliance_software · 9.9 → 9.9.2.36 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.