CVE-2019-1944: Cisco Adaptive Security Appliance Smart Tunnel Vulnerabilities
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is being established. For more information about these vulnerabilities, see the Details section of this security advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1944?
CVE-2019-1944 has been designated a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2019-1944?
To mitigate CVE-2019-1944, update your Cisco Adaptive Security Appliance Software to at least version 9.4.4.37 or a later fixed version.
Who is affected by CVE-2019-1944?
CVE-2019-1944 affects users of the Cisco Adaptive Security Appliance Software prior to version 9.4.4.37.
What type of attacks does CVE-2019-1944 allow?
CVE-2019-1944 allows authenticated local attackers to elevate their privileges to the root user or load malicious library files.
Is CVE-2019-1944 a remote vulnerability?
CVE-2019-1944 is not a remote vulnerability; it requires local authenticated access to exploit.