CVE-2023-20269

Published Sep 6, 2023

Last updated 8 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2023-20269 is a vulnerability found in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. It stems from improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. The vulnerability can be exploited in two ways: an unauthenticated, remote attacker could conduct a brute force attack to identify valid username and password combinations, or an authenticated, remote attacker could establish a clientless SSL VPN session with an unauthorized user. Exploitation may require specific conditions, such as having at least one user configured with a password in the local database or having HTTPS management authentication pointing to a valid AAA server. In the latter case, the attacker needs valid credentials. This vulnerability is actively being exploited by ransomware groups.

Description
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user. This vulnerability is due to improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. An attacker could exploit this vulnerability by specifying a default connection profile/tunnel group while conducting a brute force attack or while establishing a clientless SSL VPN session using valid credentials. A successful exploit could allow the attacker to achieve one or both of the following: Identify valid credentials that could then be used to establish an unauthorized remote access VPN session. Establish a clientless SSL VPN session (only when running Cisco ASA Software Release 9.16 or earlier). Notes: Establishing a client-based remote access VPN tunnel is not possible as these default connection profiles/tunnel groups do not and cannot have an IP address pool configured. This vulnerability does not allow an attacker to bypass authentication. To successfully establish a remote access VPN session, valid credentials are required, including a valid second factor if multi-factor authentication (MFA) is configured. Cisco will release software updates that address this vulnerability. There are workarounds that address this vulnerability.
Source
psirt@cisco.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability
Exploit added on
Sep 13, 2023
Exploit action due
Oct 4, 2023
Required action
Apply mitigations per vendor instructions for group-lock and vpn-simultaneous-logins or discontinue use of the product for unsupported devices.

Weaknesses

psirt@cisco.com
CWE-288
nvd@nist.gov
CWE-863

Social media

Hype score
Not currently trending
  1. 🔴 #Cisco ASA & FTD, Remote Code Execution, #CVE-2023-20269 (Critical) https://t.co/i4xn3Dtj9O

    @dailycve

    25 Sept 2025

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Ransomware vulns with highest exploit likelihood ⬆️ (past 30d): - CVE-2015-2291 (IQVW32.sys (BYO..) +23.34% - CVE-2024-26169 (Windows Error R..) +9.58% - CVE-2023-20269 (ASA..) +6.84% - CVE-2023-20269 (FTD..) +6.84% - CVE-2022-27510 (NetScaler ADC..) +6.76%

    @DefusedCyber

    15 Sept 2025

    8370 Impressions

    10 Retweets

    79 Likes

    38 Bookmarks

    1 Reply

    1 Quote

  3. Ransomware vulns with highest exploit likelihood ⬆️ (past 30d): - CVE-2025-53770 (SharePoint..) +25.40% - CVE-2023-20269 (ASA..) +24.24% - CVE-2023-20269 (FTD..) +24.24% - CVE-2024-26169 (Windows Error R..) +9.58% - CVE-2022-27510 (NetScaler ADC..) +6.76%

    @DefusedCyber

    8 Sept 2025

    5121 Impressions

    9 Retweets

    43 Likes

    18 Bookmarks

    2 Replies

    2 Quotes

  4. Ransomware vulns with highest exploit likelihood ⬆️ (past 30d): - CVE-2025-53770 (SharePoint..) +361.94% - CVE-2024-42057 (Zyxel Firewall..) +29.73% - CVE-2023-20269 (ASA..) +24.24% - CVE-2023-20269 (FTD..) +24.24% - CVE-2021-21974 (ESXi..) +16.07%

    @DefusedCyber

    25 Aug 2025

    936 Impressions

    1 Retweet

    14 Likes

    5 Bookmarks

    0 Replies

    1 Quote

  5. Ransomware vulns with highest exploit likelihood ⬆️ (past 30d): - CVE-2025-53770 (SharePoint..) +108108.75% - CVE-2023-20269 (ASA..) +58.41% - CVE-2023-20269 (FTD..) +58.41% - CVE-2024-42057 (Zyxel Firewall..) +29.73% - CVE-2024-37085 (ESXi..) +20.63%

    @DefusedCyber

    18 Aug 2025

    20187 Impressions

    30 Retweets

    184 Likes

    111 Bookmarks

    2 Replies

    1 Quote

Configurations