6.5mediumMedium

CVE-2019-1695

Cisco Adaptive Security Appliance Software

A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists because the software improperly filters Ethernet frames sent to an affected device. An attacker could exploit this vulnerability by sending crafted packets to the management interface of an affected device. A successful exploit could allow the attacker to bypass the Layer 2 (L2) filters and send data directly to the kernel of the affected device. A malicious frame successfully delivered would make the target device generate a specific syslog entry.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable only from the same local or logical network.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
6.5 (v3.1)
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness
CWE-284
Assigned by
psirt@cisco.com

Dates

Published
2019-05-03
Last modified
2026-08-11
Sources
NVD

Affected products

  • Cisco Adaptive Security Appliance Software- 9.8.4, 9.9 - 9.9.2.50, 9.10 - 9.10.1.17
  • Cisco Secure Firewall Threat Defense6.2.1 - 6.2.3.12, 6.3.0 - 6.3.0.3
  • Cisco Firepower 2110all versions
  • Cisco Firepower 2120all versions
  • Cisco Firepower 2130all versions
  • Cisco Firepower 2140all versions

As listed in the NVD configuration data. Not a statement about your estate.

References