CVE-2019-1934: Cisco Adaptive Security Appliance Software Web-Based Management Interface Privilege Escalation Vulnerability
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to elevate privileges and execute administrative functions on an affected device. The vulnerability is due to insufficient authorization validation. An attacker could exploit this vulnerability by logging in to an affected device as a low-privileged user and then sending specific HTTPS requests to execute administrative functions using the information retrieved during initial login.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1934?
CVE-2019-1934 is rated as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2019-1934?
To fix CVE-2019-1934, update Cisco Adaptive Security Appliance Software to a version that addresses the vulnerability.
Who is affected by CVE-2019-1934?
CVE-2019-1934 affects authenticated users of Cisco Adaptive Security Appliance Software versions up to 8.2.
What kind of attack can exploit CVE-2019-1934?
An authenticated, remote attacker can exploit CVE-2019-1934 to elevate privileges and execute administrative functions.
Is CVE-2019-1934 an authenticated or unauthenticated vulnerability?
CVE-2019-1934 is an authenticated vulnerability that requires the attacker to have valid credentials.