Evidence used
- CISA confirms exploitation in the wild.
- EPSS is 25.45% for the current model date.
BlackTreeCVE IntelligenceCisco · Adaptive Security Appliance and Firepower Threat Defense
Official source article: Cisco CISCO-SA-ASAFTD-RAVPN-AUTH-8LYFCKEC ↗. Check the applicable product and release in the original source.
CISA confirms exploitation in the wild and lists 2023-10-04 as the remediation due date.
CISA confirms exploitation in the wild and lists 2023-10-04 as the remediation due date.
Mitigation availableCisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.
Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2023-09-13. Known ransomware campaign use is recorded.
No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.
CWE-288: Authentication Bypass Using an Alternate Path or Channel. The product requires authentication, but the product has an alternate path or channel that does not require authentication.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:NCommon Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Published 6 Sept 2023 · Last source change 6 Aug 2026, 03:55 UTC · CWE-288 · Authentication Bypass Using an Alternate Path or Channel
Core structured fields are present and their contributing authorities are shown above.