First published: Wed Nov 01 2023(Updated: )
A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication policy and connect using only a valid username and password. This vulnerability is due to improper error handling during remote access VPN authentication. An attacker could exploit this vulnerability by sending crafted requests during remote access VPN session establishment. A successful exploit could allow the attacker to bypass the configured multiple certificate authentication policy while retaining the privileges and permissions associated with the original connection profile.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance | =9.8.1 | |
Cisco Adaptive Security Appliance | =9.8.1.5 | |
Cisco Adaptive Security Appliance | =9.8.1.7 | |
Cisco Adaptive Security Appliance | =9.8.2 | |
Cisco Adaptive Security Appliance | =9.8.2.8 | |
Cisco Adaptive Security Appliance | =9.8.2.14 | |
Cisco Adaptive Security Appliance | =9.8.2.15 | |
Cisco Adaptive Security Appliance | =9.8.2.17 | |
Cisco Adaptive Security Appliance Software | =9.8.2.20 | |
Cisco Adaptive Security Appliance Software | =9.8.2.24 | |
Cisco Adaptive Security Appliance Software | =9.8.2.26 | |
Cisco Adaptive Security Appliance Software | =9.8.2.28 | |
Cisco Adaptive Security Appliance Software | =9.8.2.33 | |
Cisco Adaptive Security Appliance Software | =9.8.2.35 | |
Cisco Adaptive Security Appliance Software | =9.8.2.38 | |
Cisco Adaptive Security Appliance Software | =9.8.3 | |
Cisco Adaptive Security Appliance Software | =9.8.3.8 | |
Cisco Adaptive Security Appliance Software | =9.8.3.11 | |
Cisco Adaptive Security Appliance Software | =9.8.3.14 | |
Cisco Adaptive Security Appliance Software | =9.8.3.16 | |
Cisco Adaptive Security Appliance Software | =9.8.3.18 | |
Cisco Adaptive Security Appliance Software | =9.8.3.21 | |
Cisco Adaptive Security Appliance Software | =9.8.3.26 | |
Cisco Adaptive Security Appliance Software | =9.8.3.29 | |
Cisco Adaptive Security Appliance Software | =9.8.4.8 | |
Cisco Adaptive Security Appliance Software | =9.8.4.10 | |
Cisco Adaptive Security Appliance Software | =9.8.4.12 | |
Cisco Adaptive Security Appliance Software | =9.8.4.15 | |
Cisco Adaptive Security Appliance Software | =9.8.4.17 | |
Cisco Adaptive Security Appliance Software | =9.8.4.20 | |
Cisco Adaptive Security Appliance Software | =9.8.4.22 | |
Cisco Adaptive Security Appliance Software | =9.8.4.25 | |
Cisco Adaptive Security Appliance Software | =9.8.4.26 | |
Cisco Adaptive Security Appliance Software | =9.8.4.29 | |
Cisco Adaptive Security Appliance Software | =9.8.4.32 | |
Cisco Adaptive Security Appliance Software | =9.8.4.33 | |
Cisco Adaptive Security Appliance Software | =9.8.4.34 | |
Cisco Adaptive Security Appliance Software | =9.8.4.35 | |
Cisco Adaptive Security Appliance Software | =9.8.4.39 | |
Cisco Adaptive Security Appliance Software | =9.8.4.40 | |
Cisco Adaptive Security Appliance Software | =9.8.4.41 | |
Cisco Adaptive Security Appliance Software | =9.8.4.43 | |
Cisco Adaptive Security Appliance Software | =9.8.4.44 | |
Cisco Adaptive Security Appliance Software | =9.8.4.45 | |
Cisco Adaptive Security Appliance Software | =9.8.4.46 | |
Cisco Adaptive Security Appliance Software | =9.8.4.48 | |
Cisco Adaptive Security Appliance Software | =9.12.1 | |
Cisco Adaptive Security Appliance Software | =9.12.1.2 | |
Cisco Adaptive Security Appliance Software | =9.12.1.3 | |
Cisco Adaptive Security Appliance Software | =9.12.2 | |
Cisco Adaptive Security Appliance Software | =9.12.2.1 | |
Cisco Adaptive Security Appliance Software | =9.12.2.4 | |
Cisco Adaptive Security Appliance Software | =9.12.2.5 | |
Cisco Adaptive Security Appliance Software | =9.12.2.9 | |
Cisco Adaptive Security Appliance Software | =9.12.3 | |
Cisco Adaptive Security Appliance Software | =9.12.3.2 | |
Cisco Adaptive Security Appliance Software | =9.12.3.7 | |
Cisco Adaptive Security Appliance Software | =9.12.3.9 | |
Cisco Adaptive Security Appliance Software | =9.12.3.12 | |
Cisco Adaptive Security Appliance Software | =9.12.4 | |
Cisco Adaptive Security Appliance Software | =9.12.4.2 | |
Cisco Adaptive Security Appliance Software | =9.12.4.4 | |
Cisco Adaptive Security Appliance Software | =9.12.4.7 | |
Cisco Adaptive Security Appliance Software | =9.12.4.8 | |
Cisco Adaptive Security Appliance Software | =9.12.4.10 | |
Cisco Adaptive Security Appliance Software | =9.12.4.13 | |
Cisco Adaptive Security Appliance Software | =9.12.4.18 | |
Cisco Adaptive Security Appliance Software | =9.12.4.24 | |
Cisco Adaptive Security Appliance Software | =9.12.4.26 | |
Cisco Adaptive Security Appliance Software | =9.12.4.29 | |
Cisco Adaptive Security Appliance Software | =9.12.4.30 | |
Cisco Adaptive Security Appliance Software | =9.12.4.35 | |
Cisco Adaptive Security Appliance Software | =9.12.4.37 | |
Cisco Adaptive Security Appliance Software | =9.12.4.38 | |
Cisco Adaptive Security Appliance Software | =9.12.4.39 | |
Cisco Adaptive Security Appliance Software | =9.12.4.40 | |
Cisco Adaptive Security Appliance Software | =9.12.4.41 | |
Cisco Adaptive Security Appliance Software | =9.12.4.47 | |
Cisco Adaptive Security Appliance Software | =9.12.4.48 | |
Cisco Adaptive Security Appliance Software | =9.12.4.50 | |
Cisco Adaptive Security Appliance Software | =9.12.4.52 | |
Cisco Adaptive Security Appliance Software | =9.12.4.54 | |
Cisco Adaptive Security Appliance Software | =9.12.4.55 | |
Cisco Adaptive Security Appliance Software | =9.12.4.56 | |
Cisco Adaptive Security Appliance Software | =9.12.4.58 | |
Cisco Adaptive Security Appliance Software | =9.14.1 | |
Cisco Adaptive Security Appliance Software | =9.14.1.6 | |
Cisco Adaptive Security Appliance Software | =9.14.1.10 | |
Cisco Adaptive Security Appliance Software | =9.14.1.15 | |
Cisco Adaptive Security Appliance Software | =9.14.1.19 | |
Cisco Adaptive Security Appliance Software | =9.14.1.30 | |
Cisco Adaptive Security Appliance Software | =9.14.2 | |
Cisco Adaptive Security Appliance Software | =9.14.2.4 | |
Cisco Adaptive Security Appliance Software | =9.14.2.8 | |
Cisco Adaptive Security Appliance Software | =9.14.2.13 | |
Cisco Adaptive Security Appliance Software | =9.14.2.15 | |
Cisco Adaptive Security Appliance Software | =9.14.3 | |
Cisco Adaptive Security Appliance Software | =9.14.3.1 | |
Cisco Adaptive Security Appliance Software | =9.14.3.9 | |
Cisco Adaptive Security Appliance Software | =9.14.3.11 | |
Cisco Adaptive Security Appliance Software | =9.14.3.13 | |
Cisco Adaptive Security Appliance Software | =9.14.3.15 | |
Cisco Adaptive Security Appliance Software | =9.14.3.18 | |
Cisco Adaptive Security Appliance Software | =9.14.4 | |
Cisco Adaptive Security Appliance Software | =9.14.4.6 | |
Cisco Adaptive Security Appliance Software | =9.14.4.7 | |
Cisco Adaptive Security Appliance Software | =9.14.4.12 | |
Cisco Adaptive Security Appliance Software | =9.14.4.13 | |
Cisco Adaptive Security Appliance Software | =9.14.4.14 | |
Cisco Adaptive Security Appliance Software | =9.14.4.15 | |
Cisco Adaptive Security Appliance Software | =9.14.4.17 | |
Cisco Adaptive Security Appliance Software | =9.14.4.22 | |
Cisco Adaptive Security Appliance Software | =9.14.4.23 | |
Cisco Adaptive Security Appliance Software | =9.15.1 | |
Cisco Adaptive Security Appliance Software | =9.15.1.1 | |
Cisco Adaptive Security Appliance Software | =9.15.1.7 | |
Cisco Adaptive Security Appliance Software | =9.15.1.10 | |
Cisco Adaptive Security Appliance Software | =9.15.1.15 | |
Cisco Adaptive Security Appliance Software | =9.15.1.16 | |
Cisco Adaptive Security Appliance Software | =9.15.1.17 | |
Cisco Adaptive Security Appliance Software | =9.15.1.21 | |
Cisco Adaptive Security Appliance Software | =9.16.1 | |
Cisco Adaptive Security Appliance Software | =9.16.1.28 | |
Cisco Adaptive Security Appliance Software | =9.16.2 | |
Cisco Adaptive Security Appliance Software | =9.16.2.3 | |
Cisco Adaptive Security Appliance Software | =9.16.2.7 | |
Cisco Adaptive Security Appliance Software | =9.16.2.11 | |
Cisco Adaptive Security Appliance Software | =9.16.2.13 | |
Cisco Adaptive Security Appliance Software | =9.16.2.14 | |
Cisco Adaptive Security Appliance Software | =9.16.3 | |
Cisco Adaptive Security Appliance Software | =9.16.3.3 | |
Cisco Adaptive Security Appliance Software | =9.16.3.14 | |
Cisco Adaptive Security Appliance Software | =9.16.3.15 | |
Cisco Adaptive Security Appliance Software | =9.16.3.19 | |
Cisco Adaptive Security Appliance Software | =9.16.3.23 | |
Cisco Adaptive Security Appliance Software | =9.16.4 | |
Cisco Adaptive Security Appliance Software | =9.16.4.9 | |
Cisco Adaptive Security Appliance Software | =9.16.4.14 | |
Cisco Adaptive Security Appliance Software | =9.16.4.18 | |
Cisco Adaptive Security Appliance Software | =9.16.4.19 | |
Cisco Adaptive Security Appliance Software | =9.17.1 | |
Cisco Adaptive Security Appliance Software | =9.17.1.7 | |
Cisco Adaptive Security Appliance Software | =9.17.1.9 | |
Cisco Adaptive Security Appliance Software | =9.17.1.10 | |
Cisco Adaptive Security Appliance Software | =9.17.1.11 | |
Cisco Adaptive Security Appliance Software | =9.17.1.13 | |
Cisco Adaptive Security Appliance Software | =9.17.1.15 | |
Cisco Adaptive Security Appliance Software | =9.17.1.20 | |
Cisco Adaptive Security Appliance Software | =9.17.1.30 | |
Cisco Adaptive Security Appliance Software | =9.18.1 | |
Cisco Adaptive Security Appliance Software | =9.18.1.3 | |
Cisco Adaptive Security Appliance Software | =9.18.2 | |
Cisco Adaptive Security Appliance Software | =9.18.2.5 | |
Cisco Adaptive Security Appliance Software | =9.18.2.7 | |
Cisco Adaptive Security Appliance Software | =9.18.2.8 | |
Cisco Adaptive Security Appliance Software | =9.18.3 | |
Cisco Adaptive Security Appliance Software | =9.18.3.39 | |
Cisco Adaptive Security Appliance Software | =9.18.3.46 | |
Cisco Adaptive Security Appliance Software | =9.19.1 | |
Cisco Adaptive Security Appliance Software | =9.19.1.5 | |
Cisco Adaptive Security Appliance Software | =9.19.1.9 | |
Cisco Adaptive Security Appliance Software | =9.19.1.12 | |
Cisco Firepower Threat Defense | =6.2.3 | |
Cisco Firepower Threat Defense | =6.2.3.1 | |
Cisco Firepower Threat Defense | =6.2.3.2 | |
Cisco Firepower Threat Defense | =6.2.3.3 | |
Cisco Firepower Threat Defense | =6.2.3.4 | |
Cisco Firepower Threat Defense | =6.2.3.5 | |
Cisco Firepower Threat Defense | =6.2.3.6 | |
Cisco Firepower Threat Defense | =6.2.3.7 | |
Cisco Firepower Threat Defense | =6.2.3.8 | |
Cisco Firepower Threat Defense | =6.2.3.9 | |
Cisco Firepower Threat Defense | =6.2.3.10 | |
Cisco Firepower Threat Defense | =6.2.3.11 | |
Cisco Firepower Threat Defense | =6.2.3.12 | |
Cisco Firepower Threat Defense | =6.2.3.13 | |
Cisco Firepower Threat Defense | =6.2.3.14 | |
Cisco Firepower Threat Defense | =6.2.3.15 | |
Cisco Firepower Threat Defense | =6.2.3.16 | |
Cisco Firepower Threat Defense | =6.2.3.17 | |
Cisco Firepower Threat Defense | =6.2.3.18 | |
Cisco Firepower Threat Defense | =6.4.0.5 | |
Cisco Firepower Threat Defense | =6.4.0.6 | |
Cisco Firepower Threat Defense | =6.4.0.7 | |
Cisco Firepower Threat Defense | =6.4.0.8 | |
Cisco Firepower Threat Defense | =6.4.0.9 | |
Cisco Firepower Threat Defense | =6.4.0.10 | |
Cisco Firepower Threat Defense | =6.4.0.11 | |
Cisco Firepower Threat Defense | =6.4.0.12 | |
Cisco Firepower Threat Defense | =6.4.0.13 | |
Cisco Firepower Threat Defense | =6.4.0.14 | |
Cisco Firepower Threat Defense | =6.4.0.15 | |
Cisco Firepower Threat Defense | =6.4.0.16 | |
Cisco Firepower Threat Defense | =6.6.0 | |
Cisco Firepower Threat Defense | =6.6.0.1 | |
Cisco Firepower Threat Defense | =6.6.1 | |
Cisco Firepower Threat Defense | =6.6.3 | |
Cisco Firepower Threat Defense | =6.6.4 | |
Cisco Firepower Threat Defense | =6.6.5 | |
Cisco Firepower Threat Defense | =6.6.5.1 | |
Cisco Firepower Threat Defense | =6.6.5.2 | |
Cisco Firepower Threat Defense | =6.6.7 | |
Cisco Firepower Threat Defense | =6.6.7.1 | |
Cisco Firepower Threat Defense | =6.7.0 | |
Cisco Firepower Threat Defense | =6.7.0.1 | |
Cisco Firepower Threat Defense | =6.7.0.2 | |
Cisco Firepower Threat Defense | =6.7.0.3 | |
Cisco Firepower Threat Defense | =7.0.0 | |
Cisco Firepower Threat Defense | =7.0.0.1 | |
Cisco Firepower Threat Defense | =7.0.1 | |
Cisco Firepower Threat Defense | =7.0.1.1 | |
Cisco Firepower Threat Defense | =7.0.2 | |
Cisco Firepower Threat Defense | =7.0.2.1 | |
Cisco Firepower Threat Defense | =7.0.3 | |
Cisco Firepower Threat Defense | =7.0.4 | |
Cisco Firepower Threat Defense | =7.0.5 | |
Cisco Firepower Threat Defense | =7.1.0 | |
Cisco Firepower Threat Defense | =7.1.0.1 | |
Cisco Firepower Threat Defense | =7.1.0.2 | |
Cisco Firepower Threat Defense | =7.1.0.3 | |
Cisco Firepower Threat Defense | =7.2.0 | |
Cisco Firepower Threat Defense | =7.2.0.1 | |
Cisco Firepower Threat Defense | =7.2.1 | |
Cisco Firepower Threat Defense | =7.2.2 | |
Cisco Firepower Threat Defense | =7.2.3 | |
Cisco Firepower Threat Defense | =7.2.4 | |
Cisco Firepower Threat Defense | =7.3.0 | |
Cisco Firepower Threat Defense | =7.3.1 | |
Cisco Firepower Threat Defense | =7.3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20247 has a high severity rating as it allows authenticated remote attackers to bypass multiple certificate authentication policies.
CVE-2023-20247 affects various versions of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software.
To fix CVE-2023-20247, upgrade to the latest fixed versions of Cisco ASA or FTD Software as specified in the Cisco advisory.
Yes, CVE-2023-20247 can be exploited by authenticated remote attackers.
No official workaround has been provided for CVE-2023-20247; the recommended action is to apply the necessary updates.