Cisco Adaptive Security Appliance Software Remote Access VPN Authentication Bypass Vulnerability

Related Vulnerabilities: CVE-2013-5510  

A vulnerability in the authentication code of the remote access VPN feature of Cisco ASA Software could allow an unauthenticated, remote attacker to bypass the remote VPN authentication, which could allow remote access to the inside network. The vulnerability is due to improper parsing of the LDAP response packet received from a remote AAA LDAP server when the override-account-disable option is configured in the general-attributes of the tunnel-group. An attacker could exploit this vulnerability by attempting to authenticate via remote VPN to the affected system. An exploit could allow the attacker to bypass the authentication and gain access to the network via remote VPN. Cisco has confirmed the vulnerability in a security advisory and released software updates. Only devices configured to allow Clientless or AnyConnect SSL VPN remote access and authenticate via a remote LDAP server are vulnerable, reducing the potential for exploitation.