CVE-2020-3125
Cisco Adaptive Security Appliance (ASA) vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2020-3125) was discovered in the Kerberos authentication feature of Cisco Adaptive Security Appliance (ASA) Software. The vulnerability, disclosed on May 6, 2020, allows an unauthenticated, remote attacker to impersonate the Kerberos key distribution center (KDC) and bypass authentication on affected devices configured for Kerberos authentication for VPN or local device access (Cisco Advisory, SecurityWeek).

Technical details

The vulnerability stems from insufficient identity verification of the KDC when a successful authentication response is received. An attacker could exploit this vulnerability by spoofing the KDC server response to the ASA device. The vulnerability has been assigned a high severity rating with CVSS v3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and affects multiple versions of Cisco ASA Software, including versions 9.8 through 9.13 (NVD, The Register).

Impact

If successfully exploited, this vulnerability allows attackers to bypass authentication mechanisms on affected devices, potentially gaining unauthorized access to VPN or local device resources. This is particularly concerning for organizations using Kerberos authentication for secure access control (The Register).

Mitigation and workarounds

Cisco has released software updates to address this vulnerability in ASA Software Releases 9.6.4.40, 9.8.4.15, 9.9.2.66, 9.10.1.37, 9.12.3.2, and 9.13.1.7. No workarounds are available for this vulnerability, making it critical for affected organizations to apply the provided patches (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management