Executive brief
A vulnerability in the remote access VPN feature of Cisco ASA and FTD software allows unauthenticated remote attackers to conduct brute force attacks to identify valid credentials. This is caused by improper separation of AAA between remote access VPN and other features like HTTPS management. Additionally, authenticated attackers may establish unauthorized clientless SSL VPN sessions on ASA versions 9.16 or earlier.
Affected products
- Cisco Adaptive Security Appliance (ASA) Software
- Cisco Firepower Threat Defense (FTD) Software
Timeline
- 2023-09-13: disclosed
- 2023-09-13: advisory
- 2023-09-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-09-13: exploited: Reported as exploited in the wild at time of publication.