CVE-2018-15465 describes a privilege escalation vulnerability in Cisco Adaptive Security Appliance (ASA) Software. An authenticated, but unprivileged, remote attacker can exploit improper validation of user privileges within the web management interface. This high-severity vulnerability (CVSS 8.1) allows an attacker to retrieve sensitive files, including the running configuration, or upload and replace software images on the device. While no public exploit code is available and it's not listed in CISA's KEV catalog, it has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.4.4.29CPE matchmatch criteria | cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.5, < 9.6.4.20CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.7, < 9.8.3.18CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.9, < 9.9.2.36CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.10, < 9.10.1.7CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Cisco Adaptive Security Appliance HTTP Privilege Escalation
Dec 19, 2018[R1] Cisco Adaptive Security Appliance HTTP Privilege Escalation
Dec 19, 2018[R1] Cisco Adaptive Security Appliance HTTP Privilege Escalation
Dec 19, 2018