cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
943
Views
0
Helpful
5
Replies

CVE-2023-20269 - AnyConnect

Hello All, 

can anyone tell me if there is any update regarding a patch for anyConnect CVE-2023-20269

Thanks in advance!

 

5 Replies 5

@IbrahimElbagouri57340 what software are you using, ASA of FTD? There is a hotifx for FTD 7.0.6 and 7.2.5.

You can run the advisory tool and check whether your software version is affected by this advisory. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC

 

thanks for the info,

we are unsing: 

asa9-14-4-14

asdm-7181-152

we have cisco ASA no FTD. from the link you shared it is not affected? correct?

how we can check that?

Thanks!

@IbrahimElbagouri57340 the checker is built-in to that link I provided, you put your ASA version into the checker.

RobIngram_0-1699265489905.png

and it looks like your software is affected and you need to upgrade

RobIngram_2-1699266355372.png

 

 

@Rob Ingramfor our ASA 5525-X I see the list image on software center is "asa9-14-4-23-" and based on the checker the solution for this AnyConnect vulnerablity is 9.16.4.39. do you know how we can get a solution for that or is there is any patch file that can be used in this case?

Thanks in advance! 

@IbrahimElbagouri57340 no there are no more bug fixes for that hardware, so you will be unable to patch.

You will need to replace the hardware with the new Firepower 1000 or 2000 series hardware, which does support the latest ASA software versions.