ZeroHour

CVE-2023-20269

KEV ransomwaremass

Unauthenticated Brute-Force VPN Access in Cisco ASA and Firepower Threat Defense

CISA: Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

CVSS 3.1
9.1 critical
EPSS
25%p98
Published
()
KEV added
AI analysis

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an authentication weakness (CWE-288) that allows an unauthenticated, remote attacker to conduct brute-force attacks against the SSL VPN login interface to guess valid username and password combinations, and to establish a clientless SSL VPN session as an unauthorized user under certain configurations. The attack is triggered simply by sending repeated or crafted authentication attempts to an internet-facing remote-access VPN endpoint, and vendor guidance centers on the group-lock and vpn-simultaneous-logins settings. A successful attempt gives the attacker VPN access, typically allowing them to reach the internal network as a legitimate user, which makes the flaw a common foothold for follow-on attacks including ransomware. Any organization operating a Cisco ASA or FTD with remote-access/clientless SSL VPN exposed to the internet is affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-13 with known ransomware use, and EPSS assigns it a 25.6% probability of exploitation within 30 days (98th percentile).

What to do: Apply the mitigations in the Cisco advisory: configure group-lock and per-user vpn-simultaneous-logins restrictions as directed, and update ASA/FTD to the fixed releases listed there; if the device is end-of-support/unsupported, discontinue or isolate it. Prioritize internet-facing VPN concentrators given the KEV listing and known ransomware use, and review VPN logs for unusual failed-login bursts and unexpected clientless SSL VPN sessions.

Affected
Cisco Adaptive Security Appliance (ASA)
Cisco Firepower Threat Defense (FTD)
Estimated exposure
masshundreds of thousands of internet-exposed ASA/FTD VPN devices — Cisco ASA is one of the most widely deployed firewall/remote-access VPN platforms in the world, and public internet-wide scans (e.g., Shodan/Censys) routinely enumerate several hundred thousand SSL VPN-exposed ASA/FTD devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user. This vulnerability is due to improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. An attacker could exploit this vulnerability by specifying a default connection profile/tunnel group while conducting a brute force attack or while establishing a clientless SSL VPN session using valid credentials. A successful exploit could allow the attacker to achieve one or both of the following: Identify valid credentials that could then be used to establish an unauthorized remote access VPN session. Establish a clientless SSL VPN session (only when running Cisco ASA Software Release 9.16 or earlier). Notes: Establishing a client-based remote access VPN tunnel is not possible as these default connection profiles/tunnel groups do not and cannot have an IP address pool configured. This vulnerability does not allow an attacker to bypass authentication. To successfully establish a remote access VPN session, valid credentials are required, including a valid second factor if multi-factor authentication (MFA) is configured. Cisco will release software updates that address this vulnerability. There are workarounds that address this vulnerability.

CISA Known Exploited Vulnerability
Affected
Cisco Adaptive Security Appliance and Firepower Threat Defense
Required action
Apply mitigations per vendor instructions for group-lock and vpn-simultaneous-logins or discontinue use of the product for unsupported devices.
Due date
Ransomware use
Known
Vendors
cisco
Products
adaptive security appliance software, secure firewall threat defense
Weakness
CWE-288, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news