vendor:
ASA
by:
Sean Dillon, Zachary Harding
9,8
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: ASA
Affected Version From: 9.2(3)
Affected Version To: 9.2(3)
Patch Exists: YES
Related CWE: N/A
CPE: a:cisco:asa
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Cisco ASA 9.2(3) Authentication Bypass (EXTRABACON Module)
This exploit is an additional EXTRABACON module for Cisco ASA version 9.2(3). It does not use the same shellcode as the Equation Group version, but accomplishes the same task of disabling the auth functions in less stages/bytes.
Mitigation:
Ensure that authentication is enabled and that all users have strong passwords.