Cisco has patched a vulnerability in the authorization subsystem of Cisco’s Adaptive Security Appliance (ASA) Software. An authenticated, unprivileged remote attacker could exploit the vulnerability to perform privileged actions by using the ASA web management interface.
“The vulnerability is due to improper validation of user privileges when using the web management interface. An attacker could exploit this vulnerability by sending specific HTTP requests via HTTPS to an affected device as an unprivileged user. An exploit could allow the attacker to retrieve files (including the running configuration) from the device or to upload and replace software images on the device,” Cisco noted in the advisory.
The fixed privileged escalation vulnerability (CVE-2018-15465) is rated High severity.