CVE-2019-1695 is a medium-severity vulnerability in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software that allows an unauthenticated, adjacent attacker to bypass Layer 2 filters and send data directly to the kernel. The vulnerability stems from improper filtering of Ethernet frames sent to the management interface. A successful exploit could lead to a specific syslog entry being generated on the affected device, indicating a potential compromise of the device's kernel. The vulnerability has a CVSS score of 6.5 (Medium) with an attack vector of adjacent (AV:A) and low attack complexity (AC:L), requiring no user interaction (UI:N). The potential impact is high integrity (I:H) due to the ability to send data directly to the kernel, though confidentiality (C:N) and availability (A:N) are not directly impacted. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community attention, with no social media discussion or media coverage reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.8.4CPE matchmatch criteria | cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 6.2.1, < 6.2.3.12CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
>= 6.3.0, < 6.3.0.3CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* | ||
>= 9.9, < 9.9.2.50CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.10, < 9.10.1.17CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.