SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-2054

A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are…

HIGH 7.5EPSS 0.86%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.86%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker must have the correct primary credentials in order to successfully exploit this vulnerability.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.86% probability · 56th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
cisco/asa 5500 firmware · cisco/asa 5510 firmware · cisco/asa 5512-x firmware · cisco/asa 5515-x firmware · cisco/asa 5520 firmware · cisco/asa 5525-x firmware · cisco/asa 5540 firmware · cisco/asa 5545-x firmware · cisco/asa 5550 firmware · cisco/asa 5555-x firmware · cisco/asa 5580 firmware · cisco/asa 5585-x firmware
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.