First published: Wed Aug 07 2019(Updated: )
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is being established. For more information about these vulnerabilities, see the Details section of this security advisory.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software | <9.4.4.37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1945 is classified as a high severity vulnerability that could allow privilege escalation.
To mitigate CVE-2019-1945, update Cisco Adaptive Security Appliance Software to version 9.4.4.37 or later.
CVE-2019-1945 affects users of Cisco Adaptive Security Appliance Software versions prior to 9.4.4.37.
CVE-2019-1945 allows authenticated local attackers to potentially escalate privileges but does not enable remote access by itself.
CVE-2019-1945 can allow attackers to gain root user privileges or load malicious library files during the establishment of a smart tunnel.