id: cisco-webvpn-detect info: name: Cisco WebVPN Panel - Detect author: ricardomaia severity: info description: Cisco WebVPN panel was detected. reference: - https://askanydifference.com/difference-between-cisco-clientless-ssl-vpn-and-anyconnect-with-table/ classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N cvss-score: 0 cwe-id: CWE-200 metadata: verified: true max-request: 2 fofa-query: fid="U1TP/SJklrT9VLIEpZkQNg==" google-query: intitle:"SSLVPN Service" tags: panel,cisco,vpn http: - method: GET path: - "{{BaseURL}}" - "{{BaseURL}}/webvpn.html" host-redirects: true max-redirects: 2 stop-at-first-match: true matchers-condition: and matchers: - type: word part: body words: - "CISCO" - "AnyConnect" - "SSLVPN Service" condition: or case-insensitive: true - type: regex part: header regex: - "webvpncontext=00@.+" - "webvpn=" condition: or # digest: 4a0a00473045022077a3e93a0cfeaff78a952764cadfd6ed380f57e58712bb67ae30fd27c074472a022100fb66a02cb8006a578876a98d6476651d52bd8fefbd1a2f238d8a3be6ba797ac8:922c64590222798bb761d5b6d8e72950