CVE-2013-5509: Critical severity cisco adaptive security appliance software vulnerability
The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0 before 9.0(2.6) and 9.1 before 9.1(2) allows remote attackers to bypass authentication, and obtain VPN access or administrative access, via a crafted X.509 client certificate, aka Bug ID CSCuf52468.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5509?
CVE-2013-5509 has a high severity rating due to its potential to allow unauthorized VPN and administrative access.
How do I fix CVE-2013-5509?
To resolve CVE-2013-5509, upgrade the Cisco Adaptive Security Appliance software to version 9.0(2.6) or 9.1(2) or later.
What systems are affected by CVE-2013-5509?
CVE-2013-5509 affects Cisco Adaptive Security Appliance software versions 9.0 before 9.0(2.6) and 9.1 before 9.1(2).
What type of attack does CVE-2013-5509 enable?
CVE-2013-5509 enables remote attackers to bypass authentication mechanisms using a crafted X.509 client certificate.
What is the impact of CVE-2013-5509 on security?
The impact of CVE-2013-5509 includes the potential for attackers to gain unauthorized access to VPN services and administrative controls.