First published: Wed May 07 2014(Updated: )
Cisco Adaptive Security Appliance (ASA) Software allows remote authenticated users to read files by sending a crafted URL to the HTTP server, as demonstrated by reading the running configuration, aka Bug ID CSCun78551.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2181 has been rated as a medium severity vulnerability.
To remediate CVE-2014-2181, ensure that you apply the latest software updates from Cisco for the Adaptive Security Appliance.
CVE-2014-2181 affects remote authenticated users of Cisco Adaptive Security Appliance Software.
CVE-2014-2181 is associated with an attack that allows unauthorized file access through a crafted URL.
CVE-2014-2181 can be exploited to read sensitive files, including the running configuration of the Cisco ASA.