CVE-2019-1695
Cisco Adaptive Security Appliance Software
A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulnerability exists because the software improperly filters Ethernet frames sent to an affected device. An attacker could exploit this vulnerability by sending crafted packets to the management interface of an affected device. A successful exploit could allow the attacker to bypass the Layer 2 (L2) filters and send data directly to the kernel of the affected device. A malicious frame successfully delivered would make the target device generate a specific syslog entry.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable only from the same local or logical network.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 6.5 (v3.1)
- Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N- Weakness
- CWE-284
- Assigned by
- psirt@cisco.com
Dates
- Published
- 2019-05-03
- Last modified
- 2026-08-11
- Sources
- NVD
Affected products
- Cisco Adaptive Security Appliance Software- 9.8.4, 9.9 - 9.9.2.50, 9.10 - 9.10.1.17
- Cisco Secure Firewall Threat Defense6.2.1 - 6.2.3.12, 6.3.0 - 6.3.0.3
- Cisco Firepower 2110all versions
- Cisco Firepower 2120all versions
- Cisco Firepower 2130all versions
- Cisco Firepower 2140all versions
As listed in the NVD configuration data. Not a statement about your estate.