VYPR
Unrated severityNVD Advisory· Published Jan 8, 2014· Updated Apr 29, 2026

CVE-2014-0653

CVE-2014-0653

Description

Cisco ASA Identity Firewall allows remote attackers to modify authentication state via crafted NetBIOS logout probe response.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco ASA Identity Firewall allows remote attackers to modify authentication state via crafted NetBIOS logout probe response.

Vulnerability

The Identity Firewall (IDFW) functionality in Cisco Adaptive Security Appliance (ASA) Software contains a vulnerability that allows remote attackers to trigger authentication-state modifications by sending a crafted NetBIOS logout probe response. This issue is identified by Bug ID CSCuj45340. The exact affected versions are not specified in the available references, but any ASA configuration with IDFW enabled is potentially vulnerable [1].

Exploitation

An attacker with network access to the ASA can send a specially crafted NetBIOS logout probe response to the device. No authentication is required for this action. The crafted response is processed by the IDFW component, leading to unintended changes in the authentication state of users or hosts.

Impact

Successful exploitation allows the attacker to modify the authentication state, which can result in bypassing identity-based firewall policies. This may enable unauthorized network access, privilege escalation, or disruption of identity-based access controls, compromising the confidentiality, integrity, and availability of the protected network.

Mitigation

As of the publication date (2014-01-08), Cisco has not released a software update to address this vulnerability. The Cisco Security Notice [1] does not provide a workaround. Administrators should monitor Cisco's advisory for updates. Potential mitigations include disabling IDFW if not required or restricting NetBIOS traffic to trusted sources only.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.