First published: Sat Jan 16 2016(Updated: )
Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance | =8.4.0 | |
Cisco Adaptive Security Appliance | =8.4.1 | |
Cisco Adaptive Security Appliance | =8.4.1.3 | |
Cisco Adaptive Security Appliance | =8.4.1.11 | |
Cisco Adaptive Security Appliance | =8.4.2 | |
Cisco Adaptive Security Appliance | =8.4.2.1 | |
Cisco Adaptive Security Appliance | =8.4.2.8 | |
Cisco Adaptive Security Appliance | =8.4.3 | |
Cisco Adaptive Security Appliance Software | =8.4.3.8 | |
Cisco Adaptive Security Appliance Software | =8.4.3.9 | |
Cisco Adaptive Security Appliance Software | =8.4.4 | |
Cisco Adaptive Security Appliance Software | =8.4.4.1 | |
Cisco Adaptive Security Appliance Software | =8.4.4.3 | |
Cisco Adaptive Security Appliance Software | =8.4.4.5 | |
Cisco Adaptive Security Appliance Software | =8.4.4.9 | |
Cisco Adaptive Security Appliance Software | =8.4.5 | |
Cisco Adaptive Security Appliance Software | =8.4.5.6 | |
Cisco Adaptive Security Appliance Software | =8.4.6 | |
Cisco Adaptive Security Appliance Software | =8.4.7 | |
Cisco Adaptive Security Appliance Software | =8.4.7.3 | |
Cisco Adaptive Security Appliance Software | =8.4.7.15 | |
Cisco Adaptive Security Appliance Software | =8.4.7.22 | |
Cisco Adaptive Security Appliance Software | =8.4.7.23 | |
Cisco Adaptive Security Appliance Software | =8.4.7.26 | |
Cisco Adaptive Security Appliance Software | =8.4.7.28 | |
Cisco Adaptive Security Appliance Software | =8.4.7.29 | |
Cisco Adaptive Security Appliance Software | =8.4.0 | |
Cisco Adaptive Security Appliance Software | =8.4.1 | |
Cisco Adaptive Security Appliance Software | =8.4.1.3 | |
Cisco Adaptive Security Appliance Software | =8.4.1.11 | |
Cisco Adaptive Security Appliance Software | =8.4.2 | |
Cisco Adaptive Security Appliance Software | =8.4.2.1 | |
Cisco Adaptive Security Appliance Software | =8.4.2.8 | |
Cisco Adaptive Security Appliance Software | =8.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1295 has a medium severity rating, indicating a moderate level of risk.
To mitigate CVE-2016-1295, upgrade your Cisco Adaptive Security Appliance Software to a version that addresses the vulnerability, as suggested in the Cisco Security Advisory.
CVE-2016-1295 affects several versions of Cisco Adaptive Security Appliance Software including 8.4.0 to 8.4.7.
CVE-2016-1295 allows remote attackers to obtain sensitive information during an AnyConnect authentication attempt.
Currently, there are no specific workarounds recommended for CVE-2016-1295; applying the appropriate software update is advised.