First published: Fri Feb 25 2011(Updated: )
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 before 8.3(2.13), when a Certificate Authority (CA) is configured, allow remote attackers to read arbitrary files via unspecified vectors, aka Bug ID CSCtk12352.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software | =8.0\(2\) | |
Cisco Adaptive Security Appliance Software | =8.0\(3\) | |
Cisco Adaptive Security Appliance Software | =8.0\(4\) | |
Cisco Adaptive Security Appliance Software | =8.0\(5\) | |
Cisco Adaptive Security Appliance Software | =8.1\(1\) | |
Cisco Adaptive Security Appliance Software | =8.1\(2\) | |
Cisco Adaptive Security Appliance Software | =8.2 | |
Cisco Adaptive Security Appliance Software | =8.2\(1\) | |
Cisco Adaptive Security Appliance Software | =8.2\(2\) | |
Cisco Adaptive Security Appliance Software | =8.3 | |
Cisco Adaptive Security Appliance Software | =8.0 | |
Cisco Adaptive Security Appliance Software | =8.3\(1\) | |
Cisco ASA 5500 CSC-SSM | ||
Cisco ASA 5505 | ||
Cisco ASA 5510 firmware | ||
Cisco ASA 5520 firmware | ||
Cisco ASA 5540 | ||
Cisco ASA 5550 firmware | ||
Cisco ASA 5580 | ||
Cisco PIX | ||
Cisco PIX Firewall | ||
Cisco PIX 506E | ||
Cisco PIX | ||
Cisco PIX Firewall | ||
Cisco PIX | ||
Cisco PIX | ||
Cisco PIX Firewall |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0396 is considered a high-severity vulnerability due to its potential for unauthorized file access.
To mitigate CVE-2011-0396, upgrade to Cisco Adaptive Security Appliance software versions 8.0(5.23), 8.1(2.49), 8.2(4.1), or 8.3(2.13) or later.
CVE-2011-0396 allows remote attackers to read arbitrary files from affected Cisco Adaptive Security Appliances.
CVE-2011-0396 affects Cisco Adaptive Security Appliances, specifically various versions of the ASA 5500 series with specified software versions.
Yes, CVE-2011-0396 can be exploited by remote attackers without the need for authentication.