A vulnerability in the web based management interface of cisco adaptive security appliance asa software could allow an unauthenticated remote attacker to conduct a cross site request forgery csrf attack on an affected system.
Cisco adaptive security appliance software version.
Release notes for the cisco asa device package software version 1 3 10 for aci 28 aug 2018.
Release notes for the cisco asa device package software version 1 2 12 for aci 17 may 2019.
Asa software also integrates with other critical security technologies to deliver comprehensive.
Cisco adaptive security appliance asa software is the core operating system for the cisco asa family.
Release notes for the cisco asa device package software version 1 3 12 for aci 17 may 2019.
An attacker could exploit this.
A vulnerability in the authorization subsystem of cisco adaptive security appliance asa software could allow an authenticated but unprivileged levels 0 and 1 remote attacker to perform privileged actions by using the web management interface.
The vulnerability is due to insufficient csrf protections for the web based management interface on an affected device.
Xml examples for the cisco asa device package software version 1 3 12 for aci.
An attacker could exploit this vulnerability.
Release notes for the cisco asa device package software version 1 3 11 for aci 02 nov 2018.
Cisco adaptive security appliance asa software.