CVE-2020-3125
Cisco Adaptive Security Appliance Software Kerberos Authentication Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) and bypass authentication on an affected device that is configured to perform Kerberos authentication for VPN or local device access. The vulnerability is due to insufficient identity verification of the KDC when a successful authentication response is received. An attacker could exploit this vulnerability by spoofing the KDC server response to the ASA device. This malicious response would not have been authenticated by the KDC. A successful attack could allow an attacker to bypass Kerberos authentication.
Una vulnerabilidad en la funcionalidad de autenticación de Kerberos del Cisco Adaptive Security Appliance (ASA) Software, podría permitir a un atacante remoto no autenticado suplantar al centro de distribución de claves (KDC) de Kerberos y omitir la autenticación sobre un dispositivo afectado que esté configurado para realizar la autenticación Kerberos para VPN o acceso local a dispositivos. La vulnerabilidad es debido a una verificación de identidad insuficiente del KDC cuando es recibida una respuesta de autenticación con éxito. Un atacante podría explotar esta vulnerabilidad al suplantar la respuesta del servidor KDC en el dispositivo ASA. Esta respuesta maliciosa no habría sido autenticada por el KDC. Un ataque con éxito podría permitir a un atacante omitir la autenticación de Kerberos.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2019-12-12 CVE Reserved
- 2020-05-06 CVE Published
- 2024-06-15 EPSS Updated
- 2024-11-15 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Asa 5505 Firmware Search vendor "Cisco" for product "Asa 5505 Firmware" | 9.10\(1.220\) Search vendor "Cisco" for product "Asa 5505 Firmware" and version "9.10\(1.220\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5505 Search vendor "Cisco" for product "Asa 5505" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asa 5510 Firmware Search vendor "Cisco" for product "Asa 5510 Firmware" | 9.10\(1.220\) Search vendor "Cisco" for product "Asa 5510 Firmware" and version "9.10\(1.220\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5510 Search vendor "Cisco" for product "Asa 5510" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asa 5512-x Firmware Search vendor "Cisco" for product "Asa 5512-x Firmware" | 9.10\(1.220\) Search vendor "Cisco" for product "Asa 5512-x Firmware" and version "9.10\(1.220\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5512-x Search vendor "Cisco" for product "Asa 5512-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asa 5515-x Firmware Search vendor "Cisco" for product "Asa 5515-x Firmware" | 9.10\(1.220\) Search vendor "Cisco" for product "Asa 5515-x Firmware" and version "9.10\(1.220\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5515-x Search vendor "Cisco" for product "Asa 5515-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asa 5520 Firmware Search vendor "Cisco" for product "Asa 5520 Firmware" | 9.10\(1.220\) Search vendor "Cisco" for product "Asa 5520 Firmware" and version "9.10\(1.220\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5520 Search vendor "Cisco" for product "Asa 5520" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asa 5525-x Firmware Search vendor "Cisco" for product "Asa 5525-x Firmware" | 9.10\(1.220\) Search vendor "Cisco" for product "Asa 5525-x Firmware" and version "9.10\(1.220\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5525-x Search vendor "Cisco" for product "Asa 5525-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asa 5540 Firmware Search vendor "Cisco" for product "Asa 5540 Firmware" | 9.10\(1.220\) Search vendor "Cisco" for product "Asa 5540 Firmware" and version "9.10\(1.220\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5540 Search vendor "Cisco" for product "Asa 5540" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asa 5545-x Firmware Search vendor "Cisco" for product "Asa 5545-x Firmware" | 9.10\(1.220\) Search vendor "Cisco" for product "Asa 5545-x Firmware" and version "9.10\(1.220\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5545-x Search vendor "Cisco" for product "Asa 5545-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asa 5550 Firmware Search vendor "Cisco" for product "Asa 5550 Firmware" | 9.10\(1.220\) Search vendor "Cisco" for product "Asa 5550 Firmware" and version "9.10\(1.220\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5550 Search vendor "Cisco" for product "Asa 5550" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asa 5555-x Firmware Search vendor "Cisco" for product "Asa 5555-x Firmware" | 9.10\(1.220\) Search vendor "Cisco" for product "Asa 5555-x Firmware" and version "9.10\(1.220\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5555-x Search vendor "Cisco" for product "Asa 5555-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asa 5580 Firmware Search vendor "Cisco" for product "Asa 5580 Firmware" | 9.10\(1.220\) Search vendor "Cisco" for product "Asa 5580 Firmware" and version "9.10\(1.220\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5580 Search vendor "Cisco" for product "Asa 5580" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Asa 5585-x Firmware Search vendor "Cisco" for product "Asa 5585-x Firmware" | 9.10\(1.220\) Search vendor "Cisco" for product "Asa 5585-x Firmware" and version "9.10\(1.220\)" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asa 5585-x Search vendor "Cisco" for product "Asa 5585-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | >= 9.8 < 9.8.4.15 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.8 < 9.8.4.15" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | >= 9.9 < 9.9.2.66 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.9 < 9.9.2.66" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | >= 9.10 < 9.10.1.37 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.10 < 9.10.1.37" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | >= 9.12 < 9.12.3.2 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.12 < 9.12.3.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Adaptive Security Appliance Software Search vendor "Cisco" for product "Adaptive Security Appliance Software" | >= 9.13 < 9.13.1.7 Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.13 < 9.13.1.7" | - |
Affected
|