Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerabilities are due to logical errors during traffic inspection. An attacker could exploit these vulnerabilities by sending a high volume of malicious traffic across an affected device. An exploit could allow the attacker to cause a deadlock condition, resulting in a reload of an affected device. These vulnerabilities affect Cisco ASA Software and Cisco FTD Software configured for Application Layer Protocol Inspection running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCve61540, CSCvh23085, CSCvh95456.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
7604
Subscribe
7606-s
Subscribe
7609-s
Subscribe
7613-s
Subscribe
Adaptive Security Appliance Software
Subscribe
Adaptive Security Virtual Appliance
Subscribe
Asa-5505
Subscribe
Asa-5506-x
Subscribe
Asa-5506h-x
Subscribe
Asa-5512-x
Subscribe
Asa-5515-x
Subscribe
Asa-5520
Subscribe
Asa-5540
Subscribe
Asa-5545-x
Subscribe
Asa-5555-x
Subscribe
Asa-5585-x
Subscribe
Asa 5506-x
Subscribe
Asa 5506w-x
Subscribe
Asa 5508-x
Subscribe
Asa 5510
Subscribe
Asa 5516-x
Subscribe
Asa 5525-x
Subscribe
Asa 5550
Subscribe
Asa 5555-x
Subscribe
Asa 5580
Subscribe
Catalyst 6500-e
Subscribe
Catalyst 6503-e
Subscribe
Catalyst 6504-e
Subscribe
Catalyst 6506-e
Subscribe
Catalyst 6509-e
Subscribe
Catalyst 6509-neb-a
Subscribe
Catalyst 6509-v-e
Subscribe
Catalyst 6513
Subscribe
Catalyst 6513-e
Subscribe
Firepower 2110
Subscribe
Firepower 2120
Subscribe
Firepower 2130
Subscribe
Firepower 2140
Subscribe
Firepower 4110
Subscribe
Firepower 4120
Subscribe
Firepower 4140
Subscribe
Firepower 4150
Subscribe
Firepower 9300
Subscribe
Firepower Threat Defense
Subscribe
Firepower Threat Defense Virtual
Subscribe
Isa-3000-2c2f
Subscribe
Isa-3000-4c
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-1063 | Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerabilities are due to logical errors during traffic inspection. An attacker could exploit these vulnerabilities by sending a high volume of malicious traffic across an affected device. An exploit could allow the attacker to cause a deadlock condition, resulting in a reload of an affected device. These vulnerabilities affect Cisco ASA Software and Cisco FTD Software configured for Application Layer Protocol Inspection running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCve61540, CSCvh23085, CSCvh95456. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 29 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-29T15:17:08.486Z
Reserved: 2017-11-27T00:00:00
Link: CVE-2018-0240
Updated: 2024-08-05T03:21:14.947Z
Status : Modified
Published: 2018-04-19T20:29:00.817
Modified: 2024-11-21T03:37:47.810
Link: CVE-2018-0240
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD