Security News > 2020 > May > Bored at home? Cisco has just the thing: A shed-load of security fixes to install, from a Kerberos bypass to crashes

Bored at home? Cisco has just the thing: A shed-load of security fixes to install, from a Kerberos bypass to crashes
2020-05-07 23:13

Despite the absence of a critical remote code or command execution bug, the patches include a number of serious programming blunders, particularly in the context of the network security appliances where they were found.

The Adaptive Security Appliance range - Cisco's fancy term for a firewall - is host to 11 of the bug fixes.

Among the more serious is CVE-2020-3125, a Kerberos bypass that can be exploited by "An unauthenticated, remote attacker to impersonate the Kerberos key distribution center and bypass authentication on an affected device that is configured to perform Kerberos authentication for VPN or local device access."

Other fixes include HTTP header injection bugs in Umbrella, HTTP detection security bypass bugs in multiple routers and security appliances, and a bug in Cisco Content SMA allowing users to be redirected to attack sites.

Admins are advised to test and install the patches as soon as possible, hopefully before next Tuesday when Microsoft, Intel, Adobe, and SAP are due to deliver their monthly security fixes.


News URL

https://go.theregister.co.uk/feed/www.theregister.co.uk/2020/05/07/cisco_may_patches/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2020-05-06 CVE-2020-3125 Improper Authentication vulnerability in Cisco products
A vulnerability in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) and bypass authentication on an affected device that is configured to perform Kerberos authentication for VPN or local device access.
network
low complexity
cisco CWE-287
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Cisco 4416 230 3060 1826 600 5716