Lucene search

K
cveCiscoCVE-2013-5510
HistoryOct 13, 2013 - 10:20 a.m.

CVE-2013-5510

2013-10-1310:20:04
CWE-287
cisco
web.nvd.nist.gov
24
cve-2013-5510
cisco
asa
vpn
authentication bypass
bug id
cscug83401

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

58.1%

The remote-access VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.6.x before 8.6(1.12), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.5), when an override-account-disable option is enabled, does not properly parse AAA LDAP responses, which allows remote attackers to bypass authentication via a VPN connection attempt, aka Bug ID CSCug83401.

Affected configurations

Nvd
Node
ciscoadaptive_security_appliance_softwareMatch7.0
OR
ciscoadaptive_security_appliance_softwareMatch7.0\(0\)
OR
ciscoadaptive_security_appliance_softwareMatch7.0\(1\)
OR
ciscoadaptive_security_appliance_softwareMatch7.0\(2\)
OR
ciscoadaptive_security_appliance_softwareMatch7.0\(4\)
OR
ciscoadaptive_security_appliance_softwareMatch7.0\(5\)
OR
ciscoadaptive_security_appliance_softwareMatch7.0\(5.2\)
OR
ciscoadaptive_security_appliance_softwareMatch7.0\(6\)
OR
ciscoadaptive_security_appliance_softwareMatch7.0\(6.7\)
OR
ciscoadaptive_security_appliance_softwareMatch7.0\(7\)
OR
ciscoadaptive_security_appliance_softwareMatch7.0\(8\)
OR
ciscoadaptive_security_appliance_softwareMatch7.0.1
OR
ciscoadaptive_security_appliance_softwareMatch7.0.1.4
OR
ciscoadaptive_security_appliance_softwareMatch7.0.2
OR
ciscoadaptive_security_appliance_softwareMatch7.0.4
OR
ciscoadaptive_security_appliance_softwareMatch7.0.4.3
OR
ciscoadaptive_security_appliance_softwareMatch7.0.5
OR
ciscoadaptive_security_appliance_softwareMatch7.0.6
OR
ciscoadaptive_security_appliance_softwareMatch7.0.7
OR
ciscoadaptive_security_appliance_softwareMatch7.0.8
OR
ciscoadaptive_security_appliance_softwareMatch7.0.8interim
OR
ciscoadaptive_security_appliance_softwareMatch7.1
OR
ciscoadaptive_security_appliance_softwareMatch7.1\(2\)
OR
ciscoadaptive_security_appliance_softwareMatch7.1\(2.5\)
OR
ciscoadaptive_security_appliance_softwareMatch7.1\(2.27\)
OR
ciscoadaptive_security_appliance_softwareMatch7.1\(2.48\)
OR
ciscoadaptive_security_appliance_softwareMatch7.1\(2.49\)
OR
ciscoadaptive_security_appliance_softwareMatch7.1\(5\)
OR
ciscoadaptive_security_appliance_softwareMatch7.1.1
OR
ciscoadaptive_security_appliance_softwareMatch7.1.2
OR
ciscoadaptive_security_appliance_softwareMatch7.2
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(1\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(1.22\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(2\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(2.5\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(2.7\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(2.8\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(2.10\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(2.14\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(2.15\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(2.16\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(2.17\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(2.18\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(2.19\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(2.48\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(3\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(4\)
OR
ciscoadaptive_security_appliance_softwareMatch7.2\(5\)
OR
ciscoadaptive_security_appliance_softwareMatch8.0
OR
ciscoadaptive_security_appliance_softwareMatch8.0\(2\)
OR
ciscoadaptive_security_appliance_softwareMatch8.0\(3\)
OR
ciscoadaptive_security_appliance_softwareMatch8.0\(4\)
OR
ciscoadaptive_security_appliance_softwareMatch8.0\(5\)
OR
ciscoadaptive_security_appliance_softwareMatch8.0\(5.28\)
OR
ciscoadaptive_security_appliance_softwareMatch8.0\(5.31\)
OR
ciscoadaptive_security_appliance_softwareMatch8.0.2
OR
ciscoadaptive_security_appliance_softwareMatch8.0.3
OR
ciscoadaptive_security_appliance_softwareMatch8.0.4
OR
ciscoadaptive_security_appliance_softwareMatch8.0.5
OR
ciscoadaptive_security_appliance_softwareMatch8.1
OR
ciscoadaptive_security_appliance_softwareMatch8.2
OR
ciscoadaptive_security_appliance_softwareMatch8.2\(1\)
OR
ciscoadaptive_security_appliance_softwareMatch8.2\(2\)
OR
ciscoadaptive_security_appliance_softwareMatch8.2\(3\)
OR
ciscoadaptive_security_appliance_softwareMatch8.2\(3.9\)
OR
ciscoadaptive_security_appliance_softwareMatch8.2\(4\)
OR
ciscoadaptive_security_appliance_softwareMatch8.2\(4.1\)
OR
ciscoadaptive_security_appliance_softwareMatch8.2\(4.4\)
OR
ciscoadaptive_security_appliance_softwareMatch8.2\(5\)
OR
ciscoadaptive_security_appliance_softwareMatch8.2\(5.35\)
OR
ciscoadaptive_security_appliance_softwareMatch8.2\(5.38\)
OR
ciscoadaptive_security_appliance_softwareMatch8.4
OR
ciscoadaptive_security_appliance_softwareMatch8.4\(1\)
OR
ciscoadaptive_security_appliance_softwareMatch8.4\(1.11\)
OR
ciscoadaptive_security_appliance_softwareMatch8.4\(2\)
OR
ciscoadaptive_security_appliance_softwareMatch8.4\(2.11\)
OR
ciscoadaptive_security_appliance_softwareMatch8.4\(3\)
OR
ciscoadaptive_security_appliance_softwareMatch8.4\(4.11\)
OR
ciscoadaptive_security_appliance_softwareMatch8.4\(5\)
OR
ciscoadaptive_security_appliance_softwareMatch8.6
OR
ciscoadaptive_security_appliance_softwareMatch8.6\(1\)
OR
ciscoadaptive_security_appliance_softwareMatch8.6\(1.10\)
OR
ciscoadaptive_security_appliance_softwareMatch9.0
OR
ciscoadaptive_security_appliance_softwareMatch9.1
OR
ciscoadaptive_security_appliance_softwareMatch9.1\(1.7\)
VendorProductVersionCPE
ciscoadaptive_security_appliance_software7.0cpe:2.3:o:cisco:adaptive_security_appliance_software:7.0:*:*:*:*:*:*:*
ciscoadaptive_security_appliance_software7.0(0)cpe:2.3:o:cisco:adaptive_security_appliance_software:7.0\(0\):*:*:*:*:*:*:*
ciscoadaptive_security_appliance_software7.0(1)cpe:2.3:o:cisco:adaptive_security_appliance_software:7.0\(1\):*:*:*:*:*:*:*
ciscoadaptive_security_appliance_software7.0(2)cpe:2.3:o:cisco:adaptive_security_appliance_software:7.0\(2\):*:*:*:*:*:*:*
ciscoadaptive_security_appliance_software7.0(4)cpe:2.3:o:cisco:adaptive_security_appliance_software:7.0\(4\):*:*:*:*:*:*:*
ciscoadaptive_security_appliance_software7.0(5)cpe:2.3:o:cisco:adaptive_security_appliance_software:7.0\(5\):*:*:*:*:*:*:*
ciscoadaptive_security_appliance_software7.0(5.2)cpe:2.3:o:cisco:adaptive_security_appliance_software:7.0\(5.2\):*:*:*:*:*:*:*
ciscoadaptive_security_appliance_software7.0(6)cpe:2.3:o:cisco:adaptive_security_appliance_software:7.0\(6\):*:*:*:*:*:*:*
ciscoadaptive_security_appliance_software7.0(6.7)cpe:2.3:o:cisco:adaptive_security_appliance_software:7.0\(6.7\):*:*:*:*:*:*:*
ciscoadaptive_security_appliance_software7.0(7)cpe:2.3:o:cisco:adaptive_security_appliance_software:7.0\(7\):*:*:*:*:*:*:*
Rows per page:
1-10 of 851

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

58.1%