CVE-2014-8023
Cisco ASA < 9.2.3 Authenticated Resource Access Bypass via Tunnel Group
Title source: llmDescription
Cisco Adaptive Security Appliance (ASA) Software 9.2(.3) and earlier, when challenge-response authentication is used, does not properly select tunnel groups, which allows remote authenticated users to bypass intended resource-access restrictions via a crafted tunnel-group parameter, aka Bug ID CSCtz48533.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/100922
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8023
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/72618
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031755
Vendor Advisory x_refsource_confirm
http://tools.cisco.com/security/center/viewAlert.x?alertId=37489
Scores
EPSS
0.0178
EPSS Percentile
76.0%
Details
CWE
CWE-264
Status
published
Products (1)
cisco/adaptive_security_appliance_software
< 9.2.3
Published
Feb 17, 2015
Tracked Since
Feb 18, 2026