A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to send traffic that should be denied through an affected device.
This vulnerability is due to improper error handling when an affected device that is joining a cluster runs out of memory while replicating access control rules. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Adaptive_security_appliance_software | Cisco | 9.12.1 (including) | 9.12.1 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.1.2 (including) | 9.12.1.2 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.1.3 (including) | 9.12.1.3 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.2 (including) | 9.12.2 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.2.1 (including) | 9.12.2.1 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.2.4 (including) | 9.12.2.4 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.2.5 (including) | 9.12.2.5 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.2.9 (including) | 9.12.2.9 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.3 (including) | 9.12.3 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.3.2 (including) | 9.12.3.2 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.3.7 (including) | 9.12.3.7 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.3.9 (including) | 9.12.3.9 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.3.12 (including) | 9.12.3.12 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4 (including) | 9.12.4 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.2 (including) | 9.12.4.2 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.4 (including) | 9.12.4.4 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.7 (including) | 9.12.4.7 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.8 (including) | 9.12.4.8 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.10 (including) | 9.12.4.10 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.13 (including) | 9.12.4.13 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.18 (including) | 9.12.4.18 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.24 (including) | 9.12.4.24 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.26 (including) | 9.12.4.26 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.29 (including) | 9.12.4.29 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.30 (including) | 9.12.4.30 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.35 (including) | 9.12.4.35 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.37 (including) | 9.12.4.37 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.38 (including) | 9.12.4.38 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.39 (including) | 9.12.4.39 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.40 (including) | 9.12.4.40 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.41 (including) | 9.12.4.41 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.47 (including) | 9.12.4.47 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.48 (including) | 9.12.4.48 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.50 (including) | 9.12.4.50 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.52 (including) | 9.12.4.52 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.54 (including) | 9.12.4.54 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.55 (including) | 9.12.4.55 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.56 (including) | 9.12.4.56 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.58 (including) | 9.12.4.58 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.62 (including) | 9.12.4.62 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.65 (including) | 9.12.4.65 (including) |
| Adaptive_security_appliance_software | Cisco | 9.12.4.67 (including) | 9.12.4.67 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.1 (including) | 9.16.1 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.1.28 (including) | 9.16.1.28 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.2 (including) | 9.16.2 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.2.3 (including) | 9.16.2.3 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.2.7 (including) | 9.16.2.7 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.2.11 (including) | 9.16.2.11 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.2.13 (including) | 9.16.2.13 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.2.14 (including) | 9.16.2.14 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.3 (including) | 9.16.3 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.3.3 (including) | 9.16.3.3 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.3.14 (including) | 9.16.3.14 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.3.15 (including) | 9.16.3.15 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.3.19 (including) | 9.16.3.19 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.3.23 (including) | 9.16.3.23 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4 (including) | 9.16.4 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.9 (including) | 9.16.4.9 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.14 (including) | 9.16.4.14 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.19 (including) | 9.16.4.19 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.27 (including) | 9.16.4.27 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.38 (including) | 9.16.4.38 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.39 (including) | 9.16.4.39 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.42 (including) | 9.16.4.42 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.48 (including) | 9.16.4.48 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.55 (including) | 9.16.4.55 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.57 (including) | 9.16.4.57 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.61 (including) | 9.16.4.61 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.62 (including) | 9.16.4.62 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.67 (including) | 9.16.4.67 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.70 (including) | 9.16.4.70 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.71 (including) | 9.16.4.71 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.76 (including) | 9.16.4.76 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.82 (including) | 9.16.4.82 (including) |
| Adaptive_security_appliance_software | Cisco | 9.16.4.84 (including) | 9.16.4.84 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1 (including) | 9.17.1 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1.7 (including) | 9.17.1.7 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1.9 (including) | 9.17.1.9 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1.10 (including) | 9.17.1.10 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1.11 (including) | 9.17.1.11 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1.13 (including) | 9.17.1.13 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1.15 (including) | 9.17.1.15 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1.20 (including) | 9.17.1.20 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1.30 (including) | 9.17.1.30 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1.33 (including) | 9.17.1.33 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1.39 (including) | 9.17.1.39 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1.45 (including) | 9.17.1.45 (including) |
| Adaptive_security_appliance_software | Cisco | 9.17.1.46 (including) | 9.17.1.46 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.1 (including) | 9.18.1 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.1.3 (including) | 9.18.1.3 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.2 (including) | 9.18.2 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.2.5 (including) | 9.18.2.5 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.2.7 (including) | 9.18.2.7 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.2.8 (including) | 9.18.2.8 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.3 (including) | 9.18.3 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.3.39 (including) | 9.18.3.39 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.3.46 (including) | 9.18.3.46 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.3.53 (including) | 9.18.3.53 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.3.55 (including) | 9.18.3.55 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.3.56 (including) | 9.18.3.56 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4 (including) | 9.18.4 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.5 (including) | 9.18.4.5 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.8 (including) | 9.18.4.8 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.22 (including) | 9.18.4.22 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.24 (including) | 9.18.4.24 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.29 (including) | 9.18.4.29 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.34 (including) | 9.18.4.34 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.40 (including) | 9.18.4.40 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.47 (including) | 9.18.4.47 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.50 (including) | 9.18.4.50 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.52 (including) | 9.18.4.52 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.53 (including) | 9.18.4.53 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.57 (including) | 9.18.4.57 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.66 (including) | 9.18.4.66 (including) |
| Adaptive_security_appliance_software | Cisco | 9.18.4.67 (including) | 9.18.4.67 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1 (including) | 9.19.1 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1.5 (including) | 9.19.1.5 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1.9 (including) | 9.19.1.9 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1.12 (including) | 9.19.1.12 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1.18 (including) | 9.19.1.18 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1.22 (including) | 9.19.1.22 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1.24 (including) | 9.19.1.24 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1.27 (including) | 9.19.1.27 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1.28 (including) | 9.19.1.28 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1.31 (including) | 9.19.1.31 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1.37 (including) | 9.19.1.37 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1.38 (including) | 9.19.1.38 (including) |
| Adaptive_security_appliance_software | Cisco | 9.19.1.42 (including) | 9.19.1.42 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.1 (including) | 9.20.1 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.1.5 (including) | 9.20.1.5 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.2 (including) | 9.20.2 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.2.10 (including) | 9.20.2.10 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.2.21 (including) | 9.20.2.21 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.2.22 (including) | 9.20.2.22 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.3 (including) | 9.20.3 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.3.4 (including) | 9.20.3.4 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.3.7 (including) | 9.20.3.7 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.3.9 (including) | 9.20.3.9 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.3.10 (including) | 9.20.3.10 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.3.13 (including) | 9.20.3.13 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.3.16 (including) | 9.20.3.16 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.3.20 (including) | 9.20.3.20 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.4 (including) | 9.20.4 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.4.7 (including) | 9.20.4.7 (including) |
| Adaptive_security_appliance_software | Cisco | 9.20.4.10 (including) | 9.20.4.10 (including) |
| Adaptive_security_appliance_software | Cisco | 9.22.1.1 (including) | 9.22.1.1 (including) |
| Adaptive_security_appliance_software | Cisco | 9.22.1.2 (including) | 9.22.1.2 (including) |
| Adaptive_security_appliance_software | Cisco | 9.22.1.3 (including) | 9.22.1.3 (including) |
| Adaptive_security_appliance_software | Cisco | 9.22.1.6 (including) | 9.22.1.6 (including) |
| Adaptive_security_appliance_software | Cisco | 9.22.2 (including) | 9.22.2 (including) |
| Adaptive_security_appliance_software | Cisco | 9.22.2.4 (including) | 9.22.2.4 (including) |
| Adaptive_security_appliance_software | Cisco | 9.22.2.9 (including) | 9.22.2.9 (including) |
| Adaptive_security_appliance_software | Cisco | 9.22.2.13 (including) | 9.22.2.13 (including) |
| Adaptive_security_appliance_software | Cisco | 9.23.1 (including) | 9.23.1 (including) |
| Adaptive_security_appliance_software | Cisco | 9.23.1.3 (including) | 9.23.1.3 (including) |
| Adaptive_security_appliance_software | Cisco | 9.23.1.7 (including) | 9.23.1.7 (including) |
| Adaptive_security_appliance_software | Cisco | 9.23.1.13 (including) | 9.23.1.13 (including) |
| Adaptive_security_appliance_software | Cisco | 9.23.1.19 (including) | 9.23.1.19 (including) |
Access control involves the use of several protection mechanisms such as:
When any mechanism is not applied or otherwise fails, attackers can compromise the security of the product by gaining privileges, reading sensitive information, executing commands, evading detection, etc. There are two distinct behaviors that can introduce access control weaknesses: