CVE-2013-5511: Critical severity cisco adaptive security appliance vulnerability
The Adaptive Security Device Management (ASDM) remote-management feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.7), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.6) does not properly implement the authentication-certificate option, which allows remote attackers to bypass authentication via a TCP session to an ASDM interface, aka Bug ID CSCuh44815.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5511?
CVE-2013-5511 is classified as a high-severity vulnerability.
How do I fix CVE-2013-5511?
To fix CVE-2013-5511, you should upgrade to a patched version of Cisco Adaptive Security Appliance Software as specified in the vendor's advisory.
Which software versions are affected by CVE-2013-5511?
CVE-2013-5511 affects multiple versions of Cisco ASA Software including 8.2.x, 8.3.x, 8.4.x, 8.5.x, 8.6.x, 8.7.x, 9.0.x, and 9.1.x.
What type of attack could exploit CVE-2013-5511?
CVE-2013-5511 could be exploited through remote management features, leading to unauthorized access.
Is there a workaround for CVE-2013-5511?
While the best solution is to upgrade, temporarily disabling remote management may serve as a workaround until a patch is applied.