The Adaptive Security Device Management (ASDM) remote-management feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.7), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.6) does not properly implement the authentication-certificate option, which allows remote attackers to bypass authentication via a TCP session to an ASDM interface, aka Bug ID CSCuh44815.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Adaptive_security_appliance_software | Cisco | 8.2 (including) | 8.2 (including) |
Adaptive_security_appliance_software | Cisco | 8.2(1) (including) | 8.2(1) (including) |
Adaptive_security_appliance_software | Cisco | 8.2(2) (including) | 8.2(2) (including) |
Adaptive_security_appliance_software | Cisco | 8.2(3) (including) | 8.2(3) (including) |
Adaptive_security_appliance_software | Cisco | 8.2(3.9) (including) | 8.2(3.9) (including) |
Adaptive_security_appliance_software | Cisco | 8.2(4) (including) | 8.2(4) (including) |
Adaptive_security_appliance_software | Cisco | 8.2(4.1) (including) | 8.2(4.1) (including) |
Adaptive_security_appliance_software | Cisco | 8.2(4.4) (including) | 8.2(4.4) (including) |
Adaptive_security_appliance_software | Cisco | 8.2(5) (including) | 8.2(5) (including) |
Adaptive_security_appliance_software | Cisco | 8.2(5.35) (including) | 8.2(5.35) (including) |
Adaptive_security_appliance_software | Cisco | 8.2(5.38) (including) | 8.2(5.38) (including) |
Adaptive_security_appliance_software | Cisco | 8.2.1 (including) | 8.2.1 (including) |
Adaptive_security_appliance_software | Cisco | 8.2.2 (including) | 8.2.2 (including) |
Adaptive_security_appliance_software | Cisco | 8.2.2-interim (including) | 8.2.2-interim (including) |
Adaptive_security_appliance_software | Cisco | 8.2.3 (including) | 8.2.3 (including) |
Adaptive_security_appliance_software | Cisco | 8.3(1) (including) | 8.3(1) (including) |
Adaptive_security_appliance_software | Cisco | 8.3(2) (including) | 8.3(2) (including) |
Adaptive_security_appliance_software | Cisco | 8.3(2.34) (including) | 8.3(2.34) (including) |
Adaptive_security_appliance_software | Cisco | 8.3(2.37) (including) | 8.3(2.37) (including) |
Adaptive_security_appliance_software | Cisco | 8.3.1 (including) | 8.3.1 (including) |
Adaptive_security_appliance_software | Cisco | 8.3.1-interim (including) | 8.3.1-interim (including) |
Adaptive_security_appliance_software | Cisco | 8.3.2 (including) | 8.3.2 (including) |
Adaptive_security_appliance_software | Cisco | 8.4 (including) | 8.4 (including) |
Adaptive_security_appliance_software | Cisco | 8.4(1) (including) | 8.4(1) (including) |
Adaptive_security_appliance_software | Cisco | 8.4(1.11) (including) | 8.4(1.11) (including) |
Adaptive_security_appliance_software | Cisco | 8.4(2) (including) | 8.4(2) (including) |
Adaptive_security_appliance_software | Cisco | 8.4(2.11) (including) | 8.4(2.11) (including) |
Adaptive_security_appliance_software | Cisco | 8.4(3) (including) | 8.4(3) (including) |
Adaptive_security_appliance_software | Cisco | 8.4(4.11) (including) | 8.4(4.11) (including) |
Adaptive_security_appliance_software | Cisco | 8.4(5) (including) | 8.4(5) (including) |
Adaptive_security_appliance_software | Cisco | 8.5 (including) | 8.5 (including) |
Adaptive_security_appliance_software | Cisco | 8.5(1) (including) | 8.5(1) (including) |
Adaptive_security_appliance_software | Cisco | 8.5(1.4) (including) | 8.5(1.4) (including) |
Adaptive_security_appliance_software | Cisco | 8.5(1.17) (including) | 8.5(1.17) (including) |
Adaptive_security_appliance_software | Cisco | 8.6 (including) | 8.6 (including) |
Adaptive_security_appliance_software | Cisco | 8.6(1) (including) | 8.6(1) (including) |
Adaptive_security_appliance_software | Cisco | 8.6(1.3) (including) | 8.6(1.3) (including) |
Adaptive_security_appliance_software | Cisco | 8.6(1.10) (including) | 8.6(1.10) (including) |
Adaptive_security_appliance_software | Cisco | 8.7(1.3) (including) | 8.7(1.3) (including) |
Adaptive_security_appliance_software | Cisco | 8.7.1 (including) | 8.7.1 (including) |
Adaptive_security_appliance_software | Cisco | 8.7.1.1 (including) | 8.7.1.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.0 (including) | 9.0 (including) |
Adaptive_security_appliance_software | Cisco | 9.1 (including) | 9.1 (including) |
Adaptive_security_appliance_software | Cisco | 9.1(1.7) (including) | 9.1(1.7) (including) |