Skip to main content

Cisco ASA VPN Vulnerability

Cisco have released details of a vulnerability in their Adaptive Security Appliance (ASA) software that may allow an unauthenticated attacker to remotely execute code on an affected system.

Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Cisco have released details of a vulnerability in their Adaptive Security Appliance (ASA) software that may allow an unauthenticated attacker to remotely execute code on an affected system.


Affected platforms

The following platforms are known to be affected:

Threat details

The vulnerability exists in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) functionality of the ASA software if an attempt is made to double free a memory region when the webvpn feature is enabled.

A double free error occurs when free() is called more than once as an argument for the same memory address. This can lead to memory corruption or leaks, systems crashes or altered execution flows. An attacker may target particular addresses to trick a process into executing code of their choosing.

Sending multiple, specially-crafted XML packets to a webvpn-configured interface, an attacker may be able to cause an affected system to reload and ultimately allow them execute code.

For further information:


Remediation steps

Type Step

Cisco have release patches for the affected products and systems. Users are encouraged to apply these immediately.



CVE Vulnerabilities

Last edited: 19 January 2022 1:39 pm