PT-2023-8563 · Cisco · Cisco Asa+1
CVE-2023-20269
·
Published
2023-09-06
·
Updated
2026-09-03
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Adaptive Security Appliance (ASA) (affected versions not specified)
Cisco Firepower Threat Defense (FTD) (affected versions not specified)
Description
A flaw in the remote access VPN feature of Cisco ASA and FTD software allows an unauthenticated remote attacker to perform brute force attacks to identify valid username and password combinations. Additionally, an authenticated remote attacker could establish a clientless SSL VPN session with an unauthorized user. This issue stems from improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. An attacker can exploit this by specifying a default connection profile or tunnel group. Successful exploitation may lead to the identification of valid credentials for unauthorized VPN access or the establishment of a clientless SSL VPN session on Cisco ASA versions 9.16 and earlier. Real-world exploitation has been linked to the Akira ransomware group, which used this flaw to gain network access, map environments, and target backups and servers. This issue does not allow authentication bypass; valid credentials and multi-factor authentication (MFA), if configured, are still required.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Authentication Bypass Using an Alternate Path or Channel
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Asa
Firepower Threat Defense