PT-2016-4688 · Cisco · Cisco Asa+1
CVE-2016-1295
·
Publicado
2016-01-15
·
Atualizado
2023-08-15
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Adaptive Security Appliance (ASA) Software version 8.4
Description
A remote attacker can obtain sensitive information via an AnyConnect authentication attempt. This issue allows an unauthenticated, remote attacker to access sensitive data, including the ASA Software version that is currently running on the appliance.
Recommendations
For Cisco Adaptive Security Appliance (ASA) Software version 8.4, consider restricting access to the AnyConnect authentication endpoint as a temporary workaround until a patch is available.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Anyconnect
Cisco Asa