CVE-2014-2128: Medium severity Cisco Adaptive Security Appliance Software vulnerability
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before 8.6(1.13), 9.0 before 9.0(3.8), and 9.1 before 9.1(3.2) allows remote attackers to bypass authentication via (1) a crafted cookie value within modified HTTP POST data or (2) a crafted URL, aka Bug ID CSCua85555.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2128?
CVE-2014-2128 has been rated with a medium severity score, indicating a notable risk of authentication bypass.
How do I fix CVE-2014-2128?
To remediate CVE-2014-2128, upgrade to a fixed version of Cisco Adaptive Security Appliance Software that is not affected by this vulnerability.
What systems are affected by CVE-2014-2128?
CVE-2014-2128 affects Cisco Adaptive Security Appliance Software versions 8.2, 8.3, 8.4, 8.6, 9.0, and 9.1 prior to their respective fixed releases.
Can CVE-2014-2128 be exploited remotely?
Yes, CVE-2014-2128 can be exploited remotely by attackers to bypass authentication.
Is there a workaround for CVE-2014-2128?
There are no known workarounds for CVE-2014-2128; upgrading the software is the recommended mitigation.