CVE-2011-2054
MEDIUMCisco ASA 5500 Series - Improper Authentication via Blank LDAP Password Bypass
Title source: llmDescription
A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker must have the correct primary credentials in order to successfully exploit this vulnerability.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://quickview.cloudapps.cisco.com/quickview/bug/CSCtq58884
Scores
CVSS v3
4.3
EPSS
0.0086
EPSS Percentile
53.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-287
Status
published
Products (12)
cisco/asa_5500_firmware
8.4\(1\)
cisco/asa_5510_firmware
8.4\(1\)
cisco/asa_5512-x_firmware
8.4\(1\)
cisco/asa_5515-x_firmware
8.4\(1\)
cisco/asa_5520_firmware
8.4\(1\)
cisco/asa_5525-x_firmware
8.4\(1\)
cisco/asa_5540_firmware
8.4\(1\)
cisco/asa_5545-x_firmware
8.4\(1\)
cisco/asa_5550_firmware
8.4\(1\)
cisco/asa_5555-x_firmware
8.4\(1\)
... and 2 more
Published
Feb 19, 2020
Tracked Since
Feb 18, 2026