cisco-sa-20180418-asaanyconnect: Cisco ASA Software, FTD Software, and AnyConnect Secure Mobility Client SAML Authentication Session Fixation Vulnerability
Published Apr 18, 2018
·Updated
Credit
This vulnerability was found during the resolution(a Cisco TAC support case)
Affected Software
3 affected componentsFixes available
Cisco ASA Major=9.8, <9.8.2.28, =9.7, <9.7.1.24
9.8.2.289.7.1.24
Cisco FTD Major=6.2.3, <Cisco_FTD_SSP_Hotfix_A-6.2.3.1-10.sh.REL.tar (41xx and 9300 FTD hardware platforms)
Cisco_FTD_SSP_FP2K_Hotfix_A-6.2.3.1-10.sh.REL.tar (21xx FTD hardware platform)
Cisco_FTD_Hotfix_A-6.2.3.1-10.sh.REL.tar (All other FTD hardware platforms), >=6.2.1, <=6.2.2, <Cisco_FTD_SSP_Hotfix_BD-6.2.2.3-4.sh.REL.tar (41xx and 9300 FTD hardware platforms)
Cisco_FTD_SSP_FP2K_Hotfix_BD-6.2.2.3-4.sh.REL.tar (21xx FTD hardware platform)
Cisco_FTD_Hotfix_BD-6.2.2.3-4.sh.REL.tar (All other FTD hardware platforms)
Cisco_FTD_SSP_Hotfix_A-6.2.3.1-10.sh.REL.tar (41xx and 9300 FTD hardware platforms)
Cisco_FTD_SSP_FP2K_Hotfix_A-6.2.3.1-10.sh.REL.tar (21xx FTD hardware platform)
Cisco_FTD_Hotfix_A-6.2.3.1-10.sh.REL.tar (All other FTD hardware platforms)Cisco_FTD_SSP_Hotfix_BD-6.2.2.3-4.sh.REL.tar (41xx and 9300 FTD hardware platforms)
Cisco_FTD_SSP_FP2K_Hotfix_BD-6.2.2.3-4.sh.REL.tar (21xx FTD hardware platform)
Cisco_FTD_Hotfix_BD-6.2.2.3-4.sh.REL.tar (All other FTD hardware platforms)
Cisco AnyConnect Secure Mobility Client Major
Event History
Apr 18, 2018
Advisory Published
via Cisco·04:00 PM
Frequently Asked Questions
1
What is the severity of cisco-sa-20180418-asaanyconnect?
The severity of cisco-sa-20180418-asaanyconnect is categorized as medium with a score of 6.5.
2
How do I fix cisco-sa-20180418-asaanyconnect?
To fix cisco-sa-20180418-asaanyconnect, upgrade to the latest software versions of Cisco ASA, FTD, or AnyConnect that address the SAML authentication session fixation vulnerability.
3
What products are affected by cisco-sa-20180418-asaanyconnect?
The products affected by cisco-sa-20180418-asaanyconnect include Cisco ASA Software, Cisco FTD Software, and Cisco AnyConnect Secure Mobility Client.
4
What is the nature of the vulnerability in cisco-sa-20180418-asaanyconnect?
The cisco-sa-20180418-asaanyconnect vulnerability is a session fixation issue related to SAML authentication.
5
Is user interaction required to exploit cisco-sa-20180418-asaanyconnect?
Yes, user interaction is required to exploit the cisco-sa-20180418-asaanyconnect vulnerability.