Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 99.9%; technical severity is CVSS 7.5.
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.
Who should care
- Teams operating Adaptive Security Appliance (ASA), Adaptive Security Appliance Software, Firepower Threat Defense +1 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Adaptive Security Appliance (ASA), Adaptive Security Appliance Software, Firepower Threat Defense +1 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Apply updates per vendor instructions.
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Vendor remediation
Patch and remediation links
Use the vendor source below to confirm the correct fixed version, package or mitigation for your affected product.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE
- CWE-20
- Affected versions
- Cisco Adaptive Security Appliance (ASA); Cisco Adaptive Security Appliance Software (Start Including: 9.9, End Excluding: 9.9.2.1); Cisco Firepower Threat Defense (Version: 6.2.3-851); Cisco Secure Firewall Threat Defense (Version: 6.2.3.1)
- Published
- 7 June 2018
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 99.9%
- Signal calculated at 83
External references
- Government advisory from www.cisa.gov
- Exploit information from packetstormsecurity.com
- Third-party advisory from www.securityfocus.com
- Third-party advisory from www.securitytracker.com
- Government advisory from ics-cert.us-cert.gov
- Vendor advisory from tools.cisco.com
- Exploit information from www.exploit-db.com