CVE-2014-0653
Description
Cisco ASA Identity Firewall allows remote attackers to modify authentication state via crafted NetBIOS logout probe response.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cisco ASA Identity Firewall allows remote attackers to modify authentication state via crafted NetBIOS logout probe response.
Vulnerability
The Identity Firewall (IDFW) functionality in Cisco Adaptive Security Appliance (ASA) Software contains a vulnerability that allows remote attackers to trigger authentication-state modifications by sending a crafted NetBIOS logout probe response. This issue is identified by Bug ID CSCuj45340. The exact affected versions are not specified in the available references, but any ASA configuration with IDFW enabled is potentially vulnerable [1].
Exploitation
An attacker with network access to the ASA can send a specially crafted NetBIOS logout probe response to the device. No authentication is required for this action. The crafted response is processed by the IDFW component, leading to unintended changes in the authentication state of users or hosts.
Impact
Successful exploitation allows the attacker to modify the authentication state, which can result in bypassing identity-based firewall policies. This may enable unauthorized network access, privilege escalation, or disruption of identity-based access controls, compromising the confidentiality, integrity, and availability of the protected network.
Mitigation
As of the publication date (2014-01-08), Cisco has not released a software update to address this vulnerability. The Cisco Security Notice [1] does not provide a workaround. Administrators should monitor Cisco's advisory for updates. Potential mitigations include disabling IDFW if not required or restricting NetBIOS traffic to trusted sources only.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- cpe:2.3:h:cisco:adaptive_security_appliance:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0653nvdVendor Advisory
- tools.cisco.com/security/center/viewAlert.xnvdVendor Advisory
- www.securityfocus.com/bid/64708nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1029570nvdThird Party AdvisoryVDB Entry
- osvdb.org/101834nvd
- secunia.com/advisories/56366nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/90165nvd
News mentions
0No linked articles in our index yet.