CVE-2018-15398

Description

A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL) that is configured for an interface of an affected device. The vulnerability is due to errors that could occur when the affected software constructs and applies per-user-override rules. An attacker could exploit this vulnerability by connecting to a network through an affected device that has a vulnerable configuration. A successful exploit could allow the attacker to access resources that are behind the affected device and would typically be protected by the interface ACL.

Risk Information

Base Score
4.0
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
EPSS Score
Exploitation Probability
0.317

Associated Vulnerability

VulnerabilityOS Platform
Cisco Adaptive Security Appliance Access Control List Bypass Vulnerability For Cisco Adaptive Security Appliance (ASA) SoftwareNCM
CVE-2018-15398NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706057Security Update for Cisco Adaptive Security Appliance (ASA) Software 99.17(1.69)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234