CVE Vulnerabilities

CVE-2013-1150

Improper Authentication

Published: Apr 11, 2013 | Modified: Aug 15, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

The authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8.3(2.37), 8.4 before 8.4(5.3), 8.5 and 8.6 before 8.6(1.10), 8.7 before 8.7(1.4), 9.0 before 9.0(1.1), and 9.1 before 9.1(1.2) allows remote attackers to cause a denial of service (device reload) via a crafted URL, aka Bug ID CSCud16590.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Adaptive_security_appliance_software Cisco 7.0 (including) 7.0 (including)
Adaptive_security_appliance_software Cisco 7.0(0) (including) 7.0(0) (including)
Adaptive_security_appliance_software Cisco 7.0(1) (including) 7.0(1) (including)
Adaptive_security_appliance_software Cisco 7.0(2) (including) 7.0(2) (including)
Adaptive_security_appliance_software Cisco 7.0(4) (including) 7.0(4) (including)
Adaptive_security_appliance_software Cisco 7.0(5) (including) 7.0(5) (including)
Adaptive_security_appliance_software Cisco 7.0(5.2) (including) 7.0(5.2) (including)
Adaptive_security_appliance_software Cisco 7.0(6) (including) 7.0(6) (including)
Adaptive_security_appliance_software Cisco 7.0(6.7) (including) 7.0(6.7) (including)
Adaptive_security_appliance_software Cisco 7.0(7) (including) 7.0(7) (including)
Adaptive_security_appliance_software Cisco 7.0(8) (including) 7.0(8) (including)
Adaptive_security_appliance_software Cisco 7.0.1 (including) 7.0.1 (including)
Adaptive_security_appliance_software Cisco 7.0.1.4 (including) 7.0.1.4 (including)
Adaptive_security_appliance_software Cisco 7.0.2 (including) 7.0.2 (including)
Adaptive_security_appliance_software Cisco 7.0.4 (including) 7.0.4 (including)
Adaptive_security_appliance_software Cisco 7.0.4.3 (including) 7.0.4.3 (including)
Adaptive_security_appliance_software Cisco 7.0.5 (including) 7.0.5 (including)
Adaptive_security_appliance_software Cisco 7.0.6 (including) 7.0.6 (including)
Adaptive_security_appliance_software Cisco 7.0.7 (including) 7.0.7 (including)
Adaptive_security_appliance_software Cisco 7.0.8 (including) 7.0.8 (including)
Adaptive_security_appliance_software Cisco 7.0.8-interim (including) 7.0.8-interim (including)
Adaptive_security_appliance_software Cisco 7.1 (including) 7.1 (including)
Adaptive_security_appliance_software Cisco 7.1(2) (including) 7.1(2) (including)
Adaptive_security_appliance_software Cisco 7.1(2.5) (including) 7.1(2.5) (including)
Adaptive_security_appliance_software Cisco 7.1(2.27) (including) 7.1(2.27) (including)
Adaptive_security_appliance_software Cisco 7.1(2.48) (including) 7.1(2.48) (including)
Adaptive_security_appliance_software Cisco 7.1(2.49) (including) 7.1(2.49) (including)
Adaptive_security_appliance_software Cisco 7.1(5) (including) 7.1(5) (including)
Adaptive_security_appliance_software Cisco 7.1.1 (including) 7.1.1 (including)
Adaptive_security_appliance_software Cisco 7.1.2 (including) 7.1.2 (including)
Adaptive_security_appliance_software Cisco 7.2 (including) 7.2 (including)
Adaptive_security_appliance_software Cisco 7.2(1) (including) 7.2(1) (including)
Adaptive_security_appliance_software Cisco 7.2(1.22) (including) 7.2(1.22) (including)
Adaptive_security_appliance_software Cisco 7.2(2) (including) 7.2(2) (including)
Adaptive_security_appliance_software Cisco 7.2(2.5) (including) 7.2(2.5) (including)
Adaptive_security_appliance_software Cisco 7.2(2.7) (including) 7.2(2.7) (including)
Adaptive_security_appliance_software Cisco 7.2(2.8) (including) 7.2(2.8) (including)
Adaptive_security_appliance_software Cisco 7.2(2.10) (including) 7.2(2.10) (including)
Adaptive_security_appliance_software Cisco 7.2(2.14) (including) 7.2(2.14) (including)
Adaptive_security_appliance_software Cisco 7.2(2.15) (including) 7.2(2.15) (including)
Adaptive_security_appliance_software Cisco 7.2(2.16) (including) 7.2(2.16) (including)
Adaptive_security_appliance_software Cisco 7.2(2.17) (including) 7.2(2.17) (including)
Adaptive_security_appliance_software Cisco 7.2(2.18) (including) 7.2(2.18) (including)
Adaptive_security_appliance_software Cisco 7.2(2.19) (including) 7.2(2.19) (including)
Adaptive_security_appliance_software Cisco 7.2(2.48) (including) 7.2(2.48) (including)
Adaptive_security_appliance_software Cisco 7.2(3) (including) 7.2(3) (including)
Adaptive_security_appliance_software Cisco 7.2(4) (including) 7.2(4) (including)
Adaptive_security_appliance_software Cisco 7.2(5) (including) 7.2(5) (including)
Adaptive_security_appliance_software Cisco 7.2.1 (including) 7.2.1 (including)
Adaptive_security_appliance_software Cisco 7.2.2 (including) 7.2.2 (including)
Adaptive_security_appliance_software Cisco 7.2.3 (including) 7.2.3 (including)
Adaptive_security_appliance_software Cisco 7.2.4 (including) 7.2.4 (including)
Adaptive_security_appliance_software Cisco 7.2.5 (including) 7.2.5 (including)

Potential Mitigations

References