Vulnslist

find the latest Cisco vulnerabilities

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability

cisco-sa-asaftd-ravpn-auth-8LyfCkeC · Medium · Published · Updated

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user. This vulnerability is due to improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. An attacker could exploit this vulnerability by specifying a default connection profile/tunnel group while conducting a brute force attack or while establishing a clientless SSL VPN session using valid credentials. A successful exploit could allow the attacker to achieve one or both of the following: Identify valid credentials that could then be used to establish an unauthorized remote access VPN session. Establish a clientless SSL VPN session (only when running Cisco ASA Software Release 9.16 or earlier). Notes: Establishing a client-based remote access VPN tunnel is not possible as these default connection profiles/tunnel groups do not and cannot have an IP address pool configured. This vulnerability does not allow an attacker to bypass authentication. To successfully establish a remote access VPN session, valid credentials are required, including a valid second factor if multi-factor authentication (MFA) is configured. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC

Cisco advisory · CSAF JSON

Workarounds

While there is no method to completely prevent a brute force attack attempt, you can implement the following recommendations to limit the impact of brute force attacks and to protect against unauthorized Clientless SSL VPN session establishment using the DefaultADMINGroup or DefaultL2LGroup connection profiles/tunnel groups.
Brute Force Attacks
Brute Force Attack Against the LOCAL User Database

To counter brute force attacks against the LOCAL user database, limit the number of consecutive failed login attempts that the ASA allows for a given user in the LOCAL user database using the aaa local authentication attempts max-fail number command in global configuration mode.

After a user makes the configured number of consecutive login attempts with a wrong password, the user is locked out and cannot log in successfully until the administrator either manually unlocks the user using the clear aaa local user lockout username username command or (when running Cisco ASA Software releases 9.17 and later) until 10 minutes pass. Locking or unlocking a username results in a syslog message as shown in the following example:

%ASA-6-113006: User 'test' locked out on exceeding '5' successive failed authentication attempts
%ASA-6-113007: User 'test' unlocked by 'enable_15'

Note: In Cisco ASA Software releases 9.16 and earlier, this feature does not apply to users with privilege level 15.

For further information on this feature, refer to the Cisco Secure Firewall ASA Series Command Reference ["https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/A-H/asa-command-ref-A-H/aa-ac-commands.html#wp1817806139"].

Brute Force Attacks Against an External User Database

To counter brute force attacks against an external user database, limit the number of consecutive failed login attempts per user in the external user database.

If the external user database is Cisco Identity Services Engine (ISE), this can be configured under Administration > Identity Management > Settings > User Authentication Settings > Lock/Suspend Account with Incorrect Login Attempts.

Note: Brute force attacks against an external user database are possible only if either HTTPS management authentication or at least one connection profile/tunnel group points to an external user database.
Unauthorized Clientless SSL VPN Session Establishment
Dynamic Access Policies

Administrators can configure a dynamic access policy (DAP) to terminate VPN tunnel establishment when the DefaultADMINGroup or DefaultL2LGroup connection profile/tunnel group is used. For more information on how to configure DAP, see the Configure Dynamic Access Policies ["https://www.cisco.com/c/en/us/td/docs/security/asa/asa916/asdm716/vpn/asdm-716-vpn-config/vpn-asdm-dap.html#ID-2184-000000b8"] section of the Cisco ASA Series VPN ASDM Configuration Guide.

Deny Remote Access VPN Using the Default Group Policy (DfltGrpPolicy)

When the DfltGrpPolicy is not expected to be used for remote access VPN policy assignment, administrators can prevent remote access VPN session establishment using the DefaultADMINGroup or DefaultL2LGroup connection profiles/tunnel groups by setting the vpn-simultaneous-logins option for the DfltGrpPolicy to zero, as shown in the following example:

group-policy DfltGrpPolicy attributes
vpn-simultaneous-logins 0

Notes:

Connection profiles/tunnel groups point to the DfltGrpPolicy by default. Before applying this workaround, administrators must confirm that all connection profiles/tunnel groups that are expected to be used for remote access VPN session establishment in their environment point to a custom group policy by using the default-group-policy option in tunnel-group name general-attributes configuration mode. If the default-group-policy option is not visible in the running configuration for a given connection profile/tunnel group, that connection profile/tunnel group uses the DfltGrpPolicy.
By default, custom group policies inherit the vpn-simultaneous-logins setting from the DfltGrpPolicy. Before applying this workaround, administrators must ensure that all group policies that are expected to be used with remote access VPN sessions explicitly configure the vpn-simultaneous-logins option to a value larger than zero.

Restrict Users in the LOCAL User Database

The following two workarounds apply to clientless SSL VPN session establishment that is using the DefaultADMINGroup only when HTTPS management authentication points to the LOCAL user database. They always apply to clientless SSL VPN session establishment that is using the DefaultL2LGroup.

Lock Users to a Specific Connection Profile/Tunnel Group Only

When users in the LOCAL user database are expected to be able to establish remote access VPN tunnels, administrators can use the group-lock option in username attributes configuration mode to configure a lock so that users can only connect to a specific connection profile/tunnel group. The following example shows how to lock user lockeduser to connection profile/tunnel group MyCorporateProfile:

username lockeduser attributes
group-lock value MyCorporateProfile

Prevent Users from Establishing Remote Access VPN Sessions

When users in the LOCAL user database are not expected to be able to establish remote access VPN tunnels at all, administrators can prevent these users from successfully establishing a remote access VPN tunnel by setting the vpn-simultaneous-logins option in username attributes configuration mode to zero, as shown in the following example:

username novpn attributes
vpn-simultaneous-logins 0

While these workarounds have been deployed and were proven successful in a test environment, customers should determine the applicability and effectiveness in their own environment and under their own use conditions. Customers should be aware that any workaround or mitigation that is implemented may negatively impact the functionality or performance of their network based on intrinsic customer deployment scenarios and limitations. Customers should not deploy any workarounds or mitigations before first evaluating the applicability to their own environment and any impact to such environment.

CVEsCVE-2023-20269
Cisco Bug IDsCSCwh23100, CSCwh45108
CVSS ScoreBase 5.0
Base 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.1, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.1.5, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.1.7, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2.8, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2.14, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2.15, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2.17, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2.20, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2.24, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2.26, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2.28, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2.33, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2.35, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2.38, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.3.8, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.3.11, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.3.14, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.3.16, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.3.18, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.3.21, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.3, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.3.26, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.3.29, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.3, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.7, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.8, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.10, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.12, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.15, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.17, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.2.45, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.25, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.20, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.22, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.26, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.29, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.32, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.33, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.34, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.35, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.39, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.40, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.41, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.43, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.44, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.45, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.46, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.8.4.48, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.4, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.9, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.3, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.3.2, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.3.7, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.3.12, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.3.9, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.1, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.2, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.4, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.7, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.10, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.13, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.8, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.18, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.24, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.26, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.29, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.30, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.35, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.37, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.38, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.39, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.40, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.41, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.47, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.48, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.50, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.52, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.54, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.55, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.56, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.58, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.1, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.1.10, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.1.6, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.1.15, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.1.19, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.1.30, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.2, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.2.4, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.2.8, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.2.13, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.2.15, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.3, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.3.1, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.3.9, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.3.11, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.3.13, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.3.18, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.3.15, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.4, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.4.6, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.4.7, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.4.12, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.4.13, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.4.14, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.4.15, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.4.17, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.4.22, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.4.23, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.14.4.24, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.1.28, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.3, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.7, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.11, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.13, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.2.14, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.3, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.3.3, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.3.14, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.3.15, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.3.19, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.3.23, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.4, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.4.9, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.4.14, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.4.19, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.4.27, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.16.4.38, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.7, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.9, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.10, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.11, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.13, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.15, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.20, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.17.1.30, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.1, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.1.3, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.2, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.2.5, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.2.7, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.2.8, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.3, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.3.39, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.3.46, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.3.53, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.18.3.55, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19.1, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19.1.5, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19.1.9, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19.1.12, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.19.1.18, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.20.1, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.1, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.2, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.3, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.4, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.5, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.6, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.7, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.8, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.10, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.11, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.9, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.12, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.13, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.14, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.15, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.16, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.17, Cisco Secure Firewall Threat Defense (FTD) Software 6.2.3.18, Cisco Secure Firewall Threat Defense (FTD) Software 6.6.0, Cisco Secure Firewall Threat Defense (FTD) Software 6.6.0.1, Cisco Secure Firewall Threat Defense (FTD) Software 6.6.1, Cisco Secure Firewall Threat Defense (FTD) Software 6.6.3, Cisco Secure Firewall Threat Defense (FTD) Software 6.6.4, Cisco Secure Firewall Threat Defense (FTD) Software 6.6.5, Cisco Secure Firewall Threat Defense (FTD) Software 6.6.5.1, Cisco Secure Firewall Threat Defense (FTD) Software 6.6.5.2, Cisco Secure Firewall Threat Defense (FTD) Software 6.6.7, Cisco Secure Firewall Threat Defense (FTD) Software 6.6.7.1, Cisco Secure Firewall Threat Defense (FTD) Software 6.6.7.2, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.1, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.3, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.2, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.4, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.5, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.6, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.7, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.8, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.9, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.10, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.11, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.12, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.13, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.14, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.15, Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.16, Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0, Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0.1, Cisco Secure Firewall Threat Defense (FTD) Software 7.0.1, Cisco Secure Firewall Threat Defense (FTD) Software 7.0.1.1, Cisco Secure Firewall Threat Defense (FTD) Software 7.0.2, Cisco Secure Firewall Threat Defense (FTD) Software 7.0.2.1, Cisco Secure Firewall Threat Defense (FTD) Software 7.0.3, Cisco Secure Firewall Threat Defense (FTD) Software 7.0.4, Cisco Secure Firewall Threat Defense (FTD) Software 7.0.5, Cisco Secure Firewall Threat Defense (FTD) Software 7.0.6, Cisco Secure Firewall Threat Defense (FTD) Software 7.1.0, Cisco Secure Firewall Threat Defense (FTD) Software 7.1.0.1, Cisco Secure Firewall Threat Defense (FTD) Software 7.1.0.2, Cisco Secure Firewall Threat Defense (FTD) Software 7.1.0.3, Cisco Secure Firewall Threat Defense (FTD) Software 7.2.0, Cisco Secure Firewall Threat Defense (FTD) Software 7.2.0.1, Cisco Secure Firewall Threat Defense (FTD) Software 7.2.1, Cisco Secure Firewall Threat Defense (FTD) Software 7.2.2, Cisco Secure Firewall Threat Defense (FTD) Software 7.2.3, Cisco Secure Firewall Threat Defense (FTD) Software 7.2.4, Cisco Secure Firewall Threat Defense (FTD) Software 7.2.4.1, Cisco Secure Firewall Threat Defense (FTD) Software 7.2.5, Cisco Secure Firewall Threat Defense (FTD) Software 7.3.0, Cisco Secure Firewall Threat Defense (FTD) Software 7.3.1, Cisco Secure Firewall Threat Defense (FTD) Software 7.3.1.1, Cisco Secure Firewall Threat Defense (FTD) Software 7.3.1.2, Cisco Secure Firewall Threat Defense (FTD) Software 7.4.0, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco Firepower 2100 Series, Cisco Firepower 1000 Series, Cisco ASA 5500-X Series Firewalls, Cisco 3000 Series Industrial Security Appliances (ISA), Cisco Firepower 9000 Series, Cisco Firepower 4100 Series, Cisco Adaptive Security Virtual Appliance (ASAv), Cisco Secure Firewall 3100 Series, Cisco Secure Firewall 4200 Series, Cisco Secure Firewall Threat Defense Virtual

Related Products

Product CVE Evidence
Cisco Secure Firewall Threat Defense Virtual CVE-2023-20269 Cisco OpenVuln
Cisco Secure Firewall Threat Defense (FTD) Software CVE-2023-20269 Cisco OpenVuln
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software CVE-2023-20269 Cisco OpenVuln
Cisco Secure Firewall 4200 Series CVE-2023-20269 Cisco OpenVuln
Cisco Secure Firewall 3100 Series CVE-2023-20269 Cisco OpenVuln
Cisco Firepower 9000 Series CVE-2023-20269 Cisco OpenVuln
Cisco Firepower 4100 Series CVE-2023-20269 Cisco OpenVuln
Cisco Firepower 2100 Series CVE-2023-20269 Cisco OpenVuln
Cisco Firepower 1000 Series CVE-2023-20269 Cisco OpenVuln
Cisco Adaptive Security Virtual Appliance (ASAv) CVE-2023-20269 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2023-20269 Cisco OpenVuln
Cisco ASA 5500-X Series Firewalls CVE-2023-20269 Cisco OpenVuln
Cisco 3000 Series Industrial Security Appliances (ISA) CVE-2023-20269 Cisco OpenVuln