5
CVSSv2

CVE-2016-1295

Published: 16/01/2016 Updated: 15/08/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote malicious users to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco adaptive security appliance software 8.4.3

cisco adaptive security appliance software 8.4.4.9

cisco adaptive security appliance software 8.4.4

cisco adaptive security appliance software 8.4.0

cisco adaptive security appliance software 8.4.1.3

cisco adaptive security appliance software 8.4.7.29

cisco adaptive security appliance software 8.4.1.11

cisco adaptive security appliance software 8.4.7.22

cisco adaptive security appliance software 8.4.2.1

cisco adaptive security appliance software 8.4.4.1

cisco adaptive security appliance software 8.4.7

cisco adaptive security appliance software 8.4.7.26

cisco adaptive security appliance software 8.4.5

cisco adaptive security appliance software 8.4.7.15

cisco adaptive security appliance software 8.4.4.5

cisco adaptive security appliance software 8.4.3.8

cisco adaptive security appliance software 8.4.7.23

cisco adaptive security appliance software 8.4.3.9

cisco adaptive security appliance software 8.4.6

cisco adaptive security appliance software 8.4.5.6

cisco adaptive security appliance software 8.4.7.3

cisco adaptive security appliance software 8.4.4.3

cisco adaptive security appliance software 8.4.2.8

cisco adaptive security appliance software 8.4.1

cisco adaptive security appliance software 8.4.7.28

cisco adaptive security appliance software 8.4.2

Vendor Advisories

A vulnerability in the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to access sensitive data, including the ASA Software version that is currently running on the appliance The vulnerability occurs because the Cisco ASA does not sufficiently protect sensitive data during a Cisco AnyConnect client authenti ...