LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-20269: Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 13, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Oct 4, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-20269 to its Known Exploited Vulnerabilities catalog on Sep 13, 2023, with a federal patch deadline of Oct 4, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an…

CVE-2023-20269 is an unauthorized access vulnerability in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. It can allow an unauthenticated remote attacker to perform brute-force attempts against valid username and password combinations or to establish a clientless SSL VPN session under an unauthorized user.

These products commonly sit at the network edge as firewalls and VPN gateways, so successful abuse can give attackers a foothold for further access. The vulnerability is known to have been used in ransomware activity, which raises the priority for any organization running the affected platforms.

How it works

The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). In this case it manifests as an unauthorized-access condition that lets a remote attacker without prior credentials attempt to discover valid login pairs through brute force or to open a clientless SSL VPN session that should not be permitted for that user.

An attacker would typically target the SSL VPN or related authentication interfaces exposed by ASA or FTD. Because the flaw permits unauthenticated interaction, the attacker can iterate credential guesses or force a session without first authenticating. Exact attack mechanics and any required conditions must be confirmed against the vendor advisory; public detail beyond the CISA summary is limited.

Am I affected? How to find it in your systems

Cisco ASA and FTD appliances are typically deployed as perimeter firewalls, remote-access VPN concentrators, or next-generation firewalls. Inventory every device running ASA or FTD software, including virtual instances and any high-availability pairs.

Any device still under vendor support should be checked promptly; unsupported devices require special attention because the only remaining option may be to discontinue use.

How to remediate

Follow the CISA-required action: apply the mitigations described in the vendor instructions for the group-lock and vpn-simultaneous-logins settings, or discontinue use of the product on unsupported devices. Confirm the precise configuration commands and any accompanying software updates directly in the Cisco advisory for CVE-2023-20269.

Hardening steps common to this class of authentication-bypass issues include restricting VPN access to known source networks where feasible and ensuring multi-factor authentication is enforced for all remote-access users once the core vulnerability is addressed.

If you can't patch immediately

Until the vendor mitigations can be applied, reduce exposure with compensating controls.

If your data may have been exposed

Actively exploited vulnerabilities of this type have been leveraged in ransomware campaigns, which frequently lead to data theft or encryption. If logs or other indicators suggest successful unauthorized access, treat the incident as a potential breach: isolate affected systems, preserve forensic evidence, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether credentials or other information associated with your organization have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Adaptive Security Appliance and Firepower Threat Defense
WeaknessCWE-288
Added to CISA KEVSep 13, 2023
Federal patch deadlineOct 4, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities