Description
Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerabilities are due to logical errors during traffic inspection. An attacker could exploit these vulnerabilities by sending a high volume of malicious traffic across an affected device. An exploit could allow the attacker to cause a deadlock condition, resulting in a reload of an affected device. These vulnerabilities affect Cisco ASA Software and Cisco FTD Software configured for Application Layer Protocol Inspection running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCve61540, CSCvh23085, CSCvh95456.
Published: 2018-04-19
Score: 8.6 High
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-1063 Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerabilities are due to logical errors during traffic inspection. An attacker could exploit these vulnerabilities by sending a high volume of malicious traffic across an affected device. An exploit could allow the attacker to cause a deadlock condition, resulting in a reload of an affected device. These vulnerabilities affect Cisco ASA Software and Cisco FTD Software configured for Application Layer Protocol Inspection running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCve61540, CSCvh23085, CSCvh95456.
History

Fri, 29 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco 7604 7606-s 7609-s 7613-s Adaptive Security Appliance Software Adaptive Security Virtual Appliance Asa-5505 Asa-5506-x Asa-5506h-x Asa-5512-x Asa-5515-x Asa-5520 Asa-5540 Asa-5545-x Asa-5555-x Asa-5585-x Asa 5506-x Asa 5506w-x Asa 5508-x Asa 5510 Asa 5516-x Asa 5525-x Asa 5550 Asa 5555-x Asa 5580 Catalyst 6500-e Catalyst 6503-e Catalyst 6504-e Catalyst 6506-e Catalyst 6509-e Catalyst 6509-neb-a Catalyst 6509-v-e Catalyst 6513 Catalyst 6513-e Firepower 2110 Firepower 2120 Firepower 2130 Firepower 2140 Firepower 4110 Firepower 4120 Firepower 4140 Firepower 4150 Firepower 9300 Firepower Threat Defense Firepower Threat Defense Virtual Isa-3000-2c2f Isa-3000-4c
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-29T15:17:08.486Z

Reserved: 2017-11-27T00:00:00.000Z

Link: CVE-2018-0240

cve-icon Vulnrichment

Updated: 2024-08-05T03:21:14.947Z

cve-icon NVD

Status : Modified

Published: 2018-04-19T20:29:00.817

Modified: 2024-11-21T03:37:47.810

Link: CVE-2018-0240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses