Skip to content
COOEY

EXPOSURES › CVE-2023-20269

CVE-2023-20269

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-09-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-20269 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatched

Cisco ASA and Firepower Threat Defense suffered an unpatched unauthorized access vulnerability allowing remote brute-force attacks and clientless SSL VPN sessions.

The vulnerability allowed unauthenticated remote attackers to brute-force credentials or establish unauthorized clientless SSL VPN sessions, directly enabling ransomware-linked attacks. DIB organizations must ensure all Cisco ASA and Firepower Threat Defense systems are patched immediately to prevent credential theft and unauthorized network access. This failure highlights the severe risk of relying on unpatched, actively exploited vulnerabilities in critical network security hardware.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, demonstrating a severe failure to patch known, critical flaws in widely deployed security hardware.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized