Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.106012
Kategorie:CISCO
Titel:Cisco ASA XAUTH Bypass Vulnerability (Cisco-SA-20150602-CVE-2015-0760)
Zusammenfassung:A vulnerability in IKE version 1 code of Cisco ASA Software; could allow an authenticated, remote attacker to bypass Extended Authentication (XAUTH) and; successfully log in via IPsec remote VPN.
Beschreibung:Summary:
A vulnerability in IKE version 1 code of Cisco ASA Software
could allow an authenticated, remote attacker to bypass Extended Authentication (XAUTH) and
successfully log in via IPsec remote VPN.

Vulnerability Insight:
The vulnerability is due to improper implementation of the
logic of the XAUTH code. An authenticated, remote attacker could exploit this vulnerability to
bypass authentication and gain network access to an environment an affected device is protecting.

Vulnerability Impact:
A successful exploit could be used to conduct further attacks.

Affected Software/OS:
Cisco ASA version 7.x, 8.0, 8.1 and 8.2.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:N/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2015-0760
Cisco Security Advisory: 20150602 Cisco Adaptive Security Appliance XAUTH Bypass Vulnerability
http://tools.cisco.com/security/center/viewAlert.x?alertId=39157
http://www.securitytracker.com/id/1032473
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.