Hello /r/cisco I have here a Cisco 5505 ASA on my desk and I was hoping to configure it using the ASDM. ASA 5505 ASDM Access. Select IPS/Crypto, then Security, Then ASA 3des/aes license. It should let you generate a key with just the serial, no smartnet needed. Once you have 3des/aes activated, they'll be available for SSL and VPN use. Router-switch.com is the World's Leading Network Hardware Supplier, founded in 2002. We provide network equipment that reduce the cost of network infrastructure, and is renowned for their customer service and huge supply of robust, cost-effective products.
Authors: < nixawk >
A vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code.
The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3) when enabled on a virtual or physical Cisco ASA device. An attacker could exploit this vulnerability by sending crafted SNMP packets to an SNMP-enabled interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. The attacker must know the SNMP community string to exploit this vulnerability.
Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability affects systems configured in routed and transparent firewall mode only and in single or multiple context mode. This vulnerability can be triggered by IPv4 traffic only. The attacker requires knowledge of the configured SNMP community string in SNMP version 1 and SNMP version 2c or a valid username and password for SNMP version 3.
Cisco has released software updates that address this vulnerability. Mitigations are listed in the Workarounds section of this advisory.
How to login in Cisco ASA ?
If you known nothing about the Cisco ASA device, please try to discovery something useful with nmap or custom tools/methods.
If snmp is enabled, we can try to crack the password with metasploit.
Now, CVE-2016-6366 can help us exploit remote cisco device.
If exploit successully, please try to login it with telnet. The attacker can login into the cisco device with no password.
How to check cisco version ?
How to enter into privilege mode ?
enable can be used to enter cisco config mode. Normally, the password is null.