← Back

CVE-2019-1714

nvd nist
Published: May 3, 2019Modified: Nov 21, 2024

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to successfully establish a VPN session to an affected device. The vulnerability is due to improper credential management when using NT LAN Manager (NTLM) or basic authentication. An attacker could exploit this vulnerability by opening a VPN session to an affected device after another VPN user has successfully authenticated to the affected device via SAML SSO. A successful exploit could allow the attacker to connect to secured networks behind the affected device.

Affected (5)

2 products
Firepower Threat Defense
Configuration A
5 vulnerable · 16 platform
Vulnerable SoftwareAffected Versions
Cisco
From 9.10 to 9.10.1.17
From 9.7 to 9.8.4
From 9.9 to 9.9.2.50
Cisco
From 6.2.1 to 6.2.3.12
From 6.3.0 to 6.3.0.3
Running on/withPlatform Versions
Cisco
Adaptive Security Virtual Appliance
All versions
Cisco
Asa 5506 X
All versions
Cisco
Asa 5506h X
All versions
Cisco
Asa 5506w X
All versions
Cisco
Asa 5508 X
All versions
Cisco
Asa 5516 X
All versions
Cisco
Asa 5525 X
All versions
Cisco
Asa 5545 X
All versions
Cisco
Asa 5555 X
All versions
Cisco
Firepower 2110
All versions
Cisco
Firepower 2120
All versions
Cisco
Firepower 2130
All versions
Cisco
Firepower 2140
All versions
Cisco
Firepower 4100
All versions
Cisco
Firepower 9300
All versions
Cisco
Isa 3000
All versions

Related CWEs

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.