CVE-2011-2054
7.5
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD
Description
A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker must have the correct primary credentials in order to successfully exploit this vulnerability.
Affected (12)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Asa 5500 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Asa 5510 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Asa 5512 X | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Asa 5515 X | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Asa 5520 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Asa 5525 X | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Asa 5540 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Asa 5545 X | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Asa 5550 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Asa 5555 X | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Asa 5580 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4(1) |
| Running on/with | Platform Versions |
|---|---|
Cisco Asa 5585 X | All versions |
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.