CVE-2023-20264
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2023-20264 is a vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software. It could allow an unauthenticated, remote attacker to intercept the SAML assertion of a user authenticating to a remote access VPN session. The vulnerability stems from insufficient validation of the login URL, which can be exploited by convincing a user to access a site controlled by the attacker. This would enable the attacker to modify the login URL and intercept a successful SAML assertion, potentially gaining unauthorized access to the protected network. The base severity rating for this vulnerability is medium, with low impacts on integrity and confidentiality. Remediation measures should include updating affected software versions with the appropriate security patches or upgrades provided by Cisco.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions