This vulnerability affects Cisco products that are running a vulnerable release of Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software and meet all the following conditions:
- At least one interface ACL has the per-user-override feature (per-user-override) enabled.
- At least one remote access VPN connection profile or site-to-site VPN connection profile (tunnel-group) is configured and associated with a group policy (group-policy) that specifies a filter ACL (vpn-filter).
- A VPN tunnel that is associated with an affected connection profile (tunnel-group) is currently up.
Note: In Cisco FTD Software, the per-user-override feature can be enabled via FlexConfig only.
For information about affected software releases, consult the Cisco bug ID(s) at the top of this advisory.
Determine the Cisco ASA Software Release
To determine which Cisco ASA Software release is running on a device, administrators can log in to the device, use the show version command in the CLI, and refer to the output of the command. The following example shows the output of the command for a device that is running Cisco ASA Software Release 9.4(4):
ciscoasa# show version | include Version Cisco Adaptive Security Appliance Software Version 9.4(4) Device Manager Version 7.4(1) . . .
If a device is managed by using Cisco Adaptive Security Device Manager (ASDM), administrators can also determine which release is running on a device by referring to the release information in the table that appears in the Cisco ASDM log in window or the Device Dashboard tab of the Cisco ASDM Home pane.
Determine the Cisco FTD Software Release
To determine which Cisco FTD Software release is running on a device, administrators can log in to the device, use the show version command in the CLI, and refer to the output of the command. The following example shows the output of the command for a device that is running Cisco FTD Software Release 6.2.0:
> show version
---------------------[ ftd ]---------------------
Model : Cisco ASA5525-X Threat Defense (75) Version 6.2.0 (Build 362)
UUID : 2849ba3c-ecb8-11e6-98ca-b9fc2975893c
Rules update version : 2017-03-15-001-vrt
VDB version : 279
----------------------------------------------------
from Cisco Security Advisory https://ift.tt/2ODrtZA
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.