CVE Vulnerabilities

CVE-2012-0335

Improper Authentication

Published: May 02, 2012 | Modified: Aug 15, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attempts to cut through a firewall, which allows remote attackers to obtain sensitive information via a connection attempt, aka Bug ID CSCtx42746.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Adaptive_security_appliance_software Cisco 7.2 (including) 7.2 (including)
Adaptive_security_appliance_software Cisco 7.2(1) (including) 7.2(1) (including)
Adaptive_security_appliance_software Cisco 7.2(1.22) (including) 7.2(1.22) (including)
Adaptive_security_appliance_software Cisco 7.2(2) (including) 7.2(2) (including)
Adaptive_security_appliance_software Cisco 7.2(2.5) (including) 7.2(2.5) (including)
Adaptive_security_appliance_software Cisco 7.2(2.7) (including) 7.2(2.7) (including)
Adaptive_security_appliance_software Cisco 7.2(2.8) (including) 7.2(2.8) (including)
Adaptive_security_appliance_software Cisco 7.2(2.10) (including) 7.2(2.10) (including)
Adaptive_security_appliance_software Cisco 7.2(2.14) (including) 7.2(2.14) (including)
Adaptive_security_appliance_software Cisco 7.2(2.15) (including) 7.2(2.15) (including)
Adaptive_security_appliance_software Cisco 7.2(2.16) (including) 7.2(2.16) (including)
Adaptive_security_appliance_software Cisco 7.2(2.17) (including) 7.2(2.17) (including)
Adaptive_security_appliance_software Cisco 7.2(2.18) (including) 7.2(2.18) (including)
Adaptive_security_appliance_software Cisco 7.2(2.19) (including) 7.2(2.19) (including)
Adaptive_security_appliance_software Cisco 7.2(2.48) (including) 7.2(2.48) (including)
Adaptive_security_appliance_software Cisco 7.2(3) (including) 7.2(3) (including)
Adaptive_security_appliance_software Cisco 7.2(4) (including) 7.2(4) (including)
Adaptive_security_appliance_software Cisco 7.2(5) (including) 7.2(5) (including)
Adaptive_security_appliance_software Cisco 7.2.1 (including) 7.2.1 (including)
Adaptive_security_appliance_software Cisco 7.2.2 (including) 7.2.2 (including)
Adaptive_security_appliance_software Cisco 7.2.3 (including) 7.2.3 (including)
Adaptive_security_appliance_software Cisco 7.2.4 (including) 7.2.4 (including)
Adaptive_security_appliance_software Cisco 7.2.5 (including) 7.2.5 (including)
Adaptive_security_appliance_software Cisco 8.2(1) (including) 8.2(1) (including)
Adaptive_security_appliance_software Cisco 8.2(2) (including) 8.2(2) (including)
Adaptive_security_appliance_software Cisco 8.2(3) (including) 8.2(3) (including)
Adaptive_security_appliance_software Cisco 8.2(3.9) (including) 8.2(3.9) (including)
Adaptive_security_appliance_software Cisco 8.2(4) (including) 8.2(4) (including)
Adaptive_security_appliance_software Cisco 8.2(4.1) (including) 8.2(4.1) (including)
Adaptive_security_appliance_software Cisco 8.2(4.4) (including) 8.2(4.4) (including)
Adaptive_security_appliance_software Cisco 8.2(5) (including) 8.2(5) (including)
Adaptive_security_appliance_software Cisco 8.2.1 (including) 8.2.1 (including)
Adaptive_security_appliance_software Cisco 8.2.2 (including) 8.2.2 (including)
Adaptive_security_appliance_software Cisco 8.2.2-interim (including) 8.2.2-interim (including)
Adaptive_security_appliance_software Cisco 8.2.3 (including) 8.2.3 (including)
Adaptive_security_appliance_software Cisco 8.3(1) (including) 8.3(1) (including)
Adaptive_security_appliance_software Cisco 8.3(2) (including) 8.3(2) (including)
Adaptive_security_appliance_software Cisco 8.3.1 (including) 8.3.1 (including)
Adaptive_security_appliance_software Cisco 8.3.1-interim (including) 8.3.1-interim (including)
Adaptive_security_appliance_software Cisco 8.3.2 (including) 8.3.2 (including)
Adaptive_security_appliance_software Cisco 8.4 (including) 8.4 (including)
Adaptive_security_appliance_software Cisco 8.4(1) (including) 8.4(1) (including)
Adaptive_security_appliance_software Cisco 8.4(1.11) (including) 8.4(1.11) (including)
Adaptive_security_appliance_software Cisco 8.4(2) (including) 8.4(2) (including)
Adaptive_security_appliance_software Cisco 8.4(2.11) (including) 8.4(2.11) (including)

Potential Mitigations

References