Title: Cisco VPN3K/ASA WebVPN Clientless Mode Cross-Site Scripting Vulnerability
Severity: HIGH
Description:
Cisco VPN 3000 Series Concentrators and ASA 5500 Series Adaptive Security Appliances (ASA) are prone to cross-site scripting attacks via the WebVPN Clientless Mode. This functionality allows users to connect to a VPN using their web browser, without the need of a VPN client.
The issue is due to insufficient sanitization of HTML and script code from error messages that are displayed to users. In particular, this issue is present in the 'dnserror.html' and 'connecterror.html' pages, which will be displayed to users when the affected devices display DNS and connection errors. An attacker could exploit the issue by enticing an authenticated VPN user to visit a malicious link that contains hostile HTML and script code.
This vulnerability could result in the execution of attacker-supplied HTML and script code in the session of a victim user. In the worst-case scenario, the attacker could gain unauthorized access to the VPN by stealing the WebVPN session cookie.
Cisco tracks this issue as Bug IDs CSCsd81095 and CSCse48193.
Update: Cisco states that WebVPN full-network-access mode is not affected by this issue.
Affected Products:
- Cisco ASA 5500 7.0.0
- Cisco ASA 5500 7.0.4
- Cisco ASA 5500 7.0.4 .3
- Cisco VPN 3000 Concentrator 2.0.0
- Cisco VPN 3000 Concentrator 2.5.2(A)
- Cisco VPN 3000 Concentrator 2.5.2(B)
- Cisco VPN 3000 Concentrator 2.5.2(C)
- Cisco VPN 3000 Concentrator 2.5.2(D)
- Cisco VPN 3000 Concentrator 2.5.2(F)
- Cisco VPN 3000 Concentrator 3.0.0
- Cisco VPN 3000 Concentrator 3.0.0
- Cisco VPN 3000 Concentrator 3.0.3(A)
- Cisco VPN 3000 Concentrator 3.0.3(B)
- Cisco VPN 3000 Concentrator 3.0.4
- Cisco VPN 3000 Concentrator 3.1.0
- Cisco VPN 3000 Concentrator 3.1.0(Rel)
- Cisco VPN 3000 Concentrator 3.1.1
- Cisco VPN 3000 Concentrator 3.1.2
- Cisco VPN 3000 Concentrator 3.1.4
- Cisco VPN 3000 Concentrator 3.5.0(Rel)
- Cisco VPN 3000 Concentrator 3.5.1
- Cisco VPN 3000 Concentrator 3.5.2
- Cisco VPN 3000 Concentrator 3.5.3
- Cisco VPN 3000 Concentrator 3.5.4
- Cisco VPN 3000 Concentrator 3.5.5
- Cisco VPN 3000 Concentrator 3.6.0
- Cisco VPN 3000 Concentrator 3.6.1
- Cisco VPN 3000 Concentrator 3.6.7
- Cisco VPN 3000 Concentrator 3.6.7D
- Cisco VPN 3000 Concentrator 4.0.0
- Cisco VPN 3000 Concentrator 4.0.0.x
- Cisco VPN 3000 Concentrator 4.0.1
- Cisco VPN 3000 Concentrator 4.0.5 .B
- Cisco VPN 3000 Concentrator 4.1.0 .x
- Cisco VPN 3000 Concentrator 4.1.5 .B
- Cisco VPN 3000 Concentrator 4.1.7.A
- Cisco VPN 3000 Concentrator 4.1.7.B
- Cisco VPN 3000 Concentrator 4.7.0
- Cisco VPN 3000 Concentrator 4.7.1
- Cisco VPN 3000 Concentrator 4.7.1 F
References:
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.