CVE-2011-3298

Description

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.3), 8.0 before 8.0(5.24), 8.1 before 8.1(2.50), 8.2 before 8.2(5), 8.3 before 8.3(2.18), 8.4 before 8.4(1.10), and 8.5 before 8.5(1.1) and Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7) allow remote attackers to bypass authentication via a crafted TACACS+ reply, aka Bug IDs CSCto40365 and CSCto74274.

Risk Information

Base Score
9.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.154

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module For Cisco Adaptive Security Appliance (ASA) SoftwareNCM
Multiple Vulnerabilities in Cisco Firewall Services Module For Cisco Adaptive Security Appliance (ASA) SoftwareNCM
Multiple Vulnerabilities in Cisco Firewall Services Module For NCM
Multiple Vulnerabilities in Cisco Firewall Services Module For Cisco Catalyst 6500 Series Firewall Services ModuleNCM
Improper Authentication Vulnerability (CVE-2011-3298)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706057Security Update for Cisco Adaptive Security Appliance (ASA) Software 99.17(1.69)
PATCH-1706057Security Update for Cisco Adaptive Security Appliance (ASA) Software 99.17(1.69)
PATCH-1706026Security Update for CAF-1.2.0.0
PATCH-1705358Security Update for Cisco Catalyst 6500 Series Firewall Services Module 4.0(15.3)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234