cisco-sa-20151027-cas
Cisco ASA CX Context-Aware Security Web GUI Unauthorized Access Vulnerability
Medium · Updated · Cisco
1 product with CSAF evidence
A vulnerability in the web-based GUI of Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security could allow an authenticated, remote attacker to enumerate users and read user information without belonging to a role that allows those operations. The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by sending an HTTP request to a specific URL. Cisco has not released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.