Vulnerability record · CVE-2023-20269 · published 6 September 2023
CVE-2023-20269: Cisco ASA and FTD remote access VPN AAA separation flaw
Cisco · Adaptive Security Appliance Software
Cisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can specify a default connection profile or tunnel group to brute force credentials or, with valid credentials, establish a clientless SSL VPN session as an unauthorized user. The flaw does not bypass authentication, but it enables credential discovery and unauthorized VPN access, and it has been exploited in ransomware campaigns.
Description
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user. This vulnerability is due to improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. An attacker could exploit this vulnerability by specifying a default connection profile/tunnel group while conducting a brute force attack or while establishing a clientless SSL VPN session using valid credentials. A successful exploit could allow the attacker to achieve one or both of the following: Identify valid credentials that could then be used to establish an unauthorized remote access VPN session. Establish a clientless SSL VPN session (only when running Cisco ASA Software Release 9.16 or earlier). Notes: Establishing a client-based remote access VPN tunnel is not possible as these default connection profiles/tunnel groups do not and cannot have an IP address pool configured. This vulnerability does not allow an attacker to bypass authentication. To successfully establish a remote access VPN session, valid credentials are required, including a valid second factor if multi-factor authentication (MFA) is configured. Cisco will release software updates that address this vulnerability. There are workarounds that address this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 9.1, CISA KEV listing with known ransomware use, and high EPSS percentile make this an actively exploited critical flaw.
What it is
Cisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can specify a default connection profile or tunnel group to brute force credentials or, with valid credentials, establish a clientless SSL VPN session as an unauthorized user. The flaw does not bypass authentication, but it enables credential discovery and unauthorized VPN access, and it has been exploited in ransomware campaigns.
Impact
An attacker can identify valid username and password combinations and use them to establish an unauthorized remote access VPN session, or on ASA 9.16 and earlier establish a clientless SSL VPN session. This gives network access under a legitimate account, which ransomware operators have used.
Attack surface
Reachable remotely over the network through the remote access VPN interface with no authentication or user interaction required for the brute force path; the clientless SSL VPN path requires valid credentials, including a second factor if MFA is configured.
Exploitation
Listed in CISA KEV with a 2023-10-04 remediation due date and known ransomware campaign use, and EPSS 30-day probability of 0.25453 (97.8th percentile), indicating active exploitation.
What to do
- Apply the Cisco software updates that address this vulnerability as the primary fix.
- If patching is not immediately possible, apply Cisco's workarounds for group-lock and vpn-simultaneous-logins.
- Discontinue use of unsupported devices that cannot be patched, per CISA required action.
- Enforce MFA on all remote access VPN profiles and restrict which connection profiles and tunnel groups are reachable.
- Monitor and rate-limit authentication attempts against the remote access VPN to blunt brute force activity.
Detection
- Alert on repeated failed VPN authentication attempts against default connection profiles or tunnel groups from single or distributed sources.
- Review VPN authentication logs for successful logins using default or unexpected connection profiles, especially clientless SSL VPN sessions.
- Correlate VPN account activity with post-authentication lateral movement or ransomware precursor behavior.
- Audit ASA and FTD configurations for exposed default connection profiles and confirm group-lock and vpn-simultaneous-logins settings.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-20269 to the Known Exploited Vulnerabilities catalog on 13 September 2023 as "Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions for group-lock and vpn-simultaneous-logins or discontinue use of the product for unsupported devices. Federal deadline 4 October 2023.
Ransomware crews whose documented playbooks reference this CVE: