SynopsisThe remote device is missing a vendor-supplied security patch.
DescriptionAccording to its self-reported version, Cisco Adaptive Security Appliance (ASA) Software is affected by a cross-site request forgery (CSRF) attack in the web-based management interface due to insufficient CSRF protections. An unauthenticated, remote attacker can exploit this, by persuading a user of the interface to follow a malicious link, to allow the attacker allow the attacker to perform arbitrary actions with the privilege level of the affected user. If the user has administrative privileges, the attacker could alter the configuration of, extract information from, or reload an affected device.
Please see the included Cisco BID and Cisco Security Advisory for more information.
SolutionUpgrade to the relevant fixed version referenced in Cisco bug ID CSCvj34599