Impact
A flaw in the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software allows an unauthenticated, remote attacker to send a crafted HTTP request that triggers insufficient error checking. The exploit causes the device to reload unexpectedly, resulting in a loss of availability for the VPN service while preserving confidentiality and integrity of data.
Affected Systems
Affected products are Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Based on the CPE list, versions from ASA 9.16.x up through 9.24.x and FTD 7.x through 10.x are vulnerability‑susceptible; the list includes releases such as 7.0.0, 9.16.1.28, 9.18.4.135, 9.22.2.32, and 9.24.1.155.
Risk and Exploitability
The CVSS score of 8.6 classifies the issue as high severity. The EPSS score of 1% indicates a low but nonzero likelihood of exploitation, and its inclusion in CISA's KEV catalog confirms that exploitation has been observed or is likely. The attacker only needs the ability to send HTTP traffic to the SSL VPN interface and does not require authentication; the impact is limited to denial of service for the target device.
OpenCVE Enrichment