>> All posts

CVE-2021-1585: Cisco ASDM Launcher code execution via man-in-the-middle

The short version: CVE-2021-1585 is a flaw in the Cisco Adaptive Security Device Manager (ASDM) Launcher: it fails to verify the signature of code it loads from the device, so an attacker who can intercept the connection between the Launcher and the appliance can run code on the administrator's computer. It targets the admin's client, not the firewall itself, and requires a man-in-the-middle position. Steady hands — patch, but keep the risk in proportion.

At a glance

FactDetail
Our severity takeCritical — high impact if achieved, but needs a MITM position and targets the client
CVSS v3.1 (NVD)8.1 — High · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS19.96% · 97.14th percentile (2026-07-17)
In CISA KEV?No
Known exploited?Not confirmed in the wild; public research and PoC exist
Vulnerability typeCWE-94 code injection via missing signature verification → code execution on the ASDM client
Requires authenticated session?No — but requires a man-in-the-middle network position (and often social engineering)
AffectedCisco ASDM releases before 7.18.1.152
Fixed inASDM 7.18.1.152 (paired with updated ASA software — see advisory)

What you need to know

When an administrator launches ASDM, the Launcher downloads and executes code from the appliance — but it doesn't validate that code's signature, and it doesn't validate the appliance's certificate. An attacker positioned between the Launcher and the device can therefore inject their own code, which runs on the administrator's machine with the Launcher's privileges.

  • The target is the client, not the firewall. This compromises the workstation of whoever administers the ASA, not the ASA directly — though that workstation is a high-value target in its own right.
  • It needs a privileged position. The attacker must intercept the traffic (a man-in-the-middle), and a successful attack may require social engineering to get the admin to connect.
  • Fixing it takes both sides. The complete fix updates both the ASA software and the ASDM image; clients update to the new Launcher on next connect.

How serious we see it

Critical — a real flaw with a narrow path.

The 8.1 reflects high impact (code execution) but also high attack complexity, and that complexity is the point: it isn't a remote, pre-authentication hit on an internet-facing box. It requires an attacker already able to man-in-the-middle the admin's session, and it lands on the client rather than the appliance. It isn't in CISA's KEV catalog. That said, the payoff — code execution on an administrator's machine — is serious, so patch it; just don't rank it alongside the unauthenticated appliance RCEs. The reassuring part is that it's fixable with a defined ASDM/ASA update.

Recommendations

Straight from Cisco's advisory:

  1. Patch. Update to ASDM 7.18.1.152 or later, together with the corresponding ASA software fix.
  2. Administer over trusted paths. Until patched, manage devices over SSH or serial console rather than the ASDM Launcher, and avoid connecting from untrusted networks.
  3. Watch for unsigned-load warnings. ASDM logs indicate when unsigned data is loaded; unexpected entries warrant investigation.
  4. Confirm your exposure first. Verify which ASDM release your administrators run.

How BreachRisk sees it

BreachRisk discovers internet-facing Cisco ASDM interfaces in your external footprint, fingerprints the version, and flags version-based exposures like this one. We identify and flag the affected ASDM release; because exploitation here depends on a man-in-the-middle position against an administrator, our external view focuses on surfacing the exposed, affected management interface so you can prioritize the update — and reduce how reachable that interface is in the first place.

References

See your cyber risk, proven.