首页
社区
课程
招聘
Multiple Vulnerabilities in Cisco ASA Software
发表于: 2014-4-29 21:16 753

Multiple Vulnerabilities in Cisco ASA Software

2014-4-29 21:16
753
新闻链接:b5fK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4c8G2L8$3I4K6i4K6u0W2j5$3W2K6j5$3!0Q4x3X3g2U0L8$3#2Q4x3V1k6K6k6h3y4#2M7X3W2@1P5g2)9J5c8X3y4W2L8Y4c8W2M7W2)9J5c8X3y4G2L8Y4c8W2L8Y4c8Q4x3V1k6o6K9i4y4U0L8#2y4W2j5%4g2J5K9i4c8&6b7h3c8$3K9i4y4G2M7Y4W2Q4x3V1k6U0K9i4y4U0L8#2)9J5k6s2y4S2i4K6u0V1x3U0l9I4y4o6l9@1x3o6W2Q4x3X3c8S2M7$3p5`.
新闻时间: 2014 April 18

Summary:
Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities:
Cisco ASA ASDM Privilege Escalation Vulnerability
Cisco ASA SSL VPN Privilege Escalation Vulnerability
Cisco ASA SSL VPN Authentication Bypass Vulnerability
Cisco ASA SIP Denial of Service Vulnerability
These vulnerabilities are independent of one another; a release that is affected by one of the vulnerabilities may not be affected by the others.

Successful exploitation of the Cisco ASA ASDM Privilege Escalation Vulnerability and the Cisco ASA SSL VPN Privilege Escalation Vulnerability may allow an attacker or an unprivileged user to elevate privileges and gain administrative access to the affected system.

Successful exploitation of the Cisco ASA SSL VPN Authentication Bypass Vulnerability may allow an attacker to obtain unauthorized access to the internal network via SSL VPN.

Successful exploitation of the Cisco ASA SIP Denial of Service Vulnerability may cause the exhaustion of available memory. This may cause system instability and in some cases lead to a reload of the affected system, creating a denial of service (DoS) condition.

Cisco has released free software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are available for some of the vulnerabilities. This advisory is available at the following link:
bd7K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4c8G2L8$3I4K6i4K6u0W2j5$3W2K6j5$3!0Q4x3X3g2U0L8$3#2Q4x3V1k6K6k6h3y4#2M7X3W2@1P5g2)9J5c8X3y4W2L8Y4c8W2M7W2)9J5c8X3y4G2L8Y4c8W2L8Y4c8Q4x3V1k6o6K9i4y4U0L8#2y4W2j5%4g2J5K9i4c8&6b7h3c8$3K9i4y4G2M7Y4W2Q4x3V1k6U0K9i4y4U0L8#2)9J5k6s2y4S2i4K6u0V1x3U0l9I4y4o6l9@1x3o6W2Q4x3X3c8S2M7$3p5`.

[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

收藏
免费 0
支持
分享
最新回复 (0)
游客
登录 | 注册 方可回帖
返回