Single single-sign-on SNAFU threatens three Cisco products
Credit:
cisco
Cisco has announced a suite of patches against a bug in its Security Assertion Markup Language (SAML) implementation.
As is so often the case with a language slip, the bug is inherited by multiple products. In the case of CVE-2018-0229, the affected systems are:
- Single sign-on authentication for the AnyConnect desktop mobility client;
- Adaptive Security Appliance (ASA) software; and
- Firepower Threat Defense (FTD) software.
Cisco's advisory said the bug provided a vector for an attacker to access ASA or FTD software, if they tricked someone into connecting to the security appliances.