VYPR

Adaptive Security Appliance Device Manager

by Cisco Systems, Inc.

CVEs (6)

  • CVE-2022-20829CriJun 24, 2022
    risk 0.59cvss 9.1epss 0.03

    A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker with administrative privileges to upload an ASDM image…

  • CVE-2021-1585HigJul 8, 2021
    risk 0.50cvss 7.5epss 0.20

    A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for specific code exchanged…

  • CVE-2022-20651MedJun 22, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. Cisco ADSM must be deployed in a shared workstation environment for this…

  • CVE-2019-1715MedMay 3, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to…

  • CVE-2013-1192Apr 25, 2013
    risk 0.00cvss epss 0.02

    The JAR files on Cisco Device Manager for Cisco MDS 9000 devices before 5.2.8, and Cisco Device Manager for Cisco Nexus 5000 devices, allow remote attackers to execute arbitrary commands on Windows client machines via a crafted element-manager.jnlp file, aka Bug IDs CSCty17417…

  • CVE-2007-0397Jan 20, 2007
    risk 0.00cvss epss 0.03

    The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those…