Impact
This vulnerability arises from insufficient error checking within the Remote Access SSL VPN service, which allows a remote, unauthenticated attacker to send a crafted HTTP request and force the device to reload unexpectedly. The impact is a loss of availability, resulting in a denial of service. The flaw does not affect confidentiality or integrity of data; it purely disrupts service continuity for the affected device.
Affected Systems
The affected systems are Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Specific vulnerable versions are not listed in the advisory, so any installation of these products prior to the vendor’s fix may be at risk.
Risk and Exploitability
The CVSS score of 8.6 categorizes this issue as high severity. The EPSS score of 2% indicates a low but nonzero chance of exploitation, and its presence in CISA's KEV catalog indicates that exploitation has been observed or is likely. The attack vector is remote, over the network, requiring only the ability to send HTTP traffic to the SSL VPN service. The attacker does not need authentication, and the impact is limited to service disruption on the targeted device.
OpenCVE Enrichment