In this presentation, Laura Guay and I talk about a vulnerability we discovered in Cisco ASA (CVE-2014-2127) that allows SSL VPN users to administer Cisco ASAs. We talk about how the vulnerability works, how it was fixed and discuss some offensive and defensive take aways for our fellow security professionals.
If you are interested in the demo that accompanied this presentation you can find that here: