CVE-2019-1945: Cisco Adaptive Security Appliance Smart Tunnel Vulnerabilities
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is being established. For more information about these vulnerabilities, see the Details section of this security advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1945?
CVE-2019-1945 is classified as a high severity vulnerability that could allow privilege escalation.
How do I fix CVE-2019-1945?
To mitigate CVE-2019-1945, update Cisco Adaptive Security Appliance Software to version 9.4.4.37 or later.
Who is affected by CVE-2019-1945?
CVE-2019-1945 affects users of Cisco Adaptive Security Appliance Software versions prior to 9.4.4.37.
Can CVE-2019-1945 allow remote access?
CVE-2019-1945 allows authenticated local attackers to potentially escalate privileges but does not enable remote access by itself.
What kind of attacks can CVE-2019-1945 facilitate?
CVE-2019-1945 can allow attackers to gain root user privileges or load malicious library files during the establishment of a smart tunnel.