CVE-2019-1701

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
03/05/2019
Last modified:
15/08/2023

Description

Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the WebVPN portal of an affected device. The vulnerabilities exist because the software insufficiently validates user-supplied input on an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information. An attacker would need administrator privileges on the device to exploit these vulnerabilities.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* 9.4.4.34 (excluding)
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* 9.5 (including) 9.6.4.25 (excluding)
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* 9.7 (including) 9.8.4 (excluding)
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* 9.9 (including) 9.9.2.50 (excluding)
cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* 9.10 (including) 9.10.1.17 (excluding)
cpe:2.3:h:cisco:asa_5505:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asa_5510:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asa_5512-x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asa_5515-x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asa_5520:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asa_5525-x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asa_5540:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asa_5545-x:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asa_5550:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:asa_5555-x:-:*:*:*:*:*:*:*