CVE-2014-0739: Cisco Adaptive Security Appliance Software
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
Race condition in the Phone Proxy component in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to bypass sec_db authentication and provide certain pass-through services to untrusted devices via a crafted configuration-file TFTP request, aka Bug ID CSCuj66766.
Affected products
- Cisco Adaptive Security Appliance Software: version 9.1(3) only
Published 2014-02-22. Last modified 2026-06-17.