<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability CSCvg35618 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-adaptive-security-appliance-remote-code-execution-and/m-p/3424302#M132995</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dennis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both firewalls have the AnyConnect software in their directory and both firewalls have the AnyConnect pointers in the configuration before the upgrade. I have done upgrades in the past to address Cisco vulnerabilities on these firewalls with no AnyConnect issues. Also, I use the same procedure by upgrading the standby first, switching the firewall roles, upgrading the active, and then switching back the firewall roles. No downtime since there are IPSec connections in use. I cannot see any reason why an upgrade would remove configuration statements. I reviewed the notes for this vulnerability and there is no mention of reentering the AnyConnect pointers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Feb 2018 13:36:25 GMT</pubDate>
    <dc:creator>msanclimenti</dc:creator>
    <dc:date>2018-02-12T13:36:25Z</dc:date>
    <item>
      <title>Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability CSCvg35618</title>
      <link>https://community.cisco.com/t5/network-security/cisco-adaptive-security-appliance-remote-code-execution-and/m-p/3424300#M132990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Over the weekend I upgraded a couple of ASA5545X firewalls to v9.6.4-3 that are in a HA pair. This upgrade fix the vulnerability CSC35618. A few hours later I received calls that no one could connect to the VPN using AnyConnect. The users were trying to access the VPN using their Windows 10 laptops. I was able to verify this. The error was&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;"The AnyConnect package on the secure gateway could not be located. You may&lt;BR /&gt;be experiencing network connectivity issues. Please try connecting again."&lt;/STRONG&gt; I verified this error with my Windows 10 laptop. I was able to access the firewalls using my iPad with the AnyConnect client. Looking over the ASA configuration the AnyConnect image pointers under the webvpn section of the configuration was removed. I had to reenter the pointers and the VPN was operational.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The original ASA code was v 9.6.3(1) and VPN was working before the upgrade. If you need to do this upgrade and you are using AnyConnect, please verify the AnyConnect pointers are still present after the upgrade is completed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt; enable outside-internet&lt;/P&gt;&lt;P&gt; &lt;EM&gt;&lt;STRONG&gt;anyconnect image disk0:/anyconnect-win-4.5.01044-webdeploy-k9.pkg 1 (missing after the upgrade)&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt; anyconnect image disk0:/anyconnect-macos-4.5.01044-webdeploy-k9.pkg 2 (missing after the upgrade)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt; anyconnect image disk0:/anyconnect-linux64-4.5.01044-webdeploy-k9.pkg 3 (missing after the upgrade)&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt; anyconnect enable&lt;/P&gt;&lt;P&gt; tunnel-group-list enable&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 13:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-adaptive-security-appliance-remote-code-execution-and/m-p/3424300#M132990</guid>
      <dc:creator>msanclimenti</dc:creator>
      <dc:date>2018-02-12T13:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability CSCvg35618</title>
      <link>https://community.cisco.com/t5/network-security/cisco-adaptive-security-appliance-remote-code-execution-and/m-p/3424301#M132992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This will happen during the upgrade process you failover from the active to&lt;/P&gt;&lt;P&gt;the standby unit if the standby unit does not have the Anyconnect image on&lt;/P&gt;&lt;P&gt;it you will lose the pointer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Mon, Feb 12, 2018 at 9:46 AM, Michael Sanclimenti &amp;lt;community@cisco.com&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 13:28:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-adaptive-security-appliance-remote-code-execution-and/m-p/3424301#M132992</guid>
      <dc:creator>ddefoort</dc:creator>
      <dc:date>2018-02-12T13:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability CSCvg35618</title>
      <link>https://community.cisco.com/t5/network-security/cisco-adaptive-security-appliance-remote-code-execution-and/m-p/3424302#M132995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dennis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both firewalls have the AnyConnect software in their directory and both firewalls have the AnyConnect pointers in the configuration before the upgrade. I have done upgrades in the past to address Cisco vulnerabilities on these firewalls with no AnyConnect issues. Also, I use the same procedure by upgrading the standby first, switching the firewall roles, upgrading the active, and then switching back the firewall roles. No downtime since there are IPSec connections in use. I cannot see any reason why an upgrade would remove configuration statements. I reviewed the notes for this vulnerability and there is no mention of reentering the AnyConnect pointers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 13:36:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-adaptive-security-appliance-remote-code-execution-and/m-p/3424302#M132995</guid>
      <dc:creator>msanclimenti</dc:creator>
      <dc:date>2018-02-12T13:36:25Z</dc:date>
    </item>
  </channel>
</rss>

