First published: Wed Aug 10 2022(Updated: )
A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device. This vulnerability is due to improper validation of input that is passed to the VPN web client services component before being returned to the browser that is in use. An attacker could exploit this vulnerability by persuading a user to visit a website that is designed to pass malicious requests to a device that is running Cisco ASA Software or Cisco FTD Software and has web services endpoints supporting VPN features enabled. A successful exploit could allow the attacker to reflect malicious input from the affected device to the browser that is in use and conduct browser-based attacks, including cross-site scripting attacks. The attacker could not directly impact the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-webvpn-LOeKsNmO
Credit: James Kettle PortswiggerCisco would also like to thank Valerio Brussani NoZero for reporting additional details about this vulnerability
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software | ||
Cisco Firepower Management Center (FMC) and Firepower Threat Defense (FTD) Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-asa-webvpn-LOeKsNmO is considered to be high due to the potential for unauthenticated remote attacks.
To fix cisco-sa-asa-webvpn-LOeKsNmO, upgrade your Cisco Adaptive Security Appliance Software or Cisco Firepower Threat Defense Software to the latest patched version.
Users of Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software are affected by cisco-sa-asa-webvpn-LOeKsNmO.
If cisco-sa-asa-webvpn-LOeKsNmO is exploited, attackers could conduct browser-based attacks against users of the affected devices.
Yes, cisco-sa-asa-webvpn-LOeKsNmO allows unauthenticated remote attackers to target vulnerable devices.