A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using the web management interface. An attacker could exploit this vulnerability by sending specific HTTP requests via HTTPS to an affected device as an unprivileged user. An exploit could allow the attacker to retrieve files (including the running configuration) from the device or to upload and replace software images on the device.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2018-12-24T14:00:00Z
Updated: 2024-09-17T02:47:36.834Z
Reserved: 2018-08-17T00:00:00
Link: CVE-2018-15465
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-12-24T14:29:00.723
Modified: 2024-11-21T03:50:51.913
Link: CVE-2018-15465
Redhat
No data.