CVE-2018-0296

Cisco Adaptive Security Appliance (ASA): Denial-of-Service

As of , CVE-2018-0296 in Cisco Adaptive Security Appliance (ASA) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 3 November 2021
US federal deadline
3 May 2022181 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
Not availableCISA listed it before 4 February 2022, where the EPSS files we read begin.
Public exploit
1 Metasploit module and 2 Exploit-DB entries
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.

CISA's description

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.

The CVE record's description, from cisco

CVE published
7 June 2018
Assigned by
cisco
CVSS
7.5 High (CVSS 3.1, from CISA-ADP)
CWE-20
Improper Input Validation
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
partial

Timeline

  1. The CVE record was published.
  2. Exploit-DB published an exploit (EDB-ID 44956).
  3. Exploit-DB published an exploit (EDB-ID 47220).
  4. CISA added it to its list of exploited vulnerabilities.
  5. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Adaptive Security Appliance (ASA): other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2016-6366SNMP Buffer OverflowCisco Adaptive Security Appliance (ASA)Patch this weekMetasploit module; EPSS 0.880.88
CVE-2014-2120Cross-Site Scripting (XSS)Cisco Adaptive Security Appliance (ASA)Patch soon0.23
CVE-2016-6367CLI Remote Code ExecutionCisco Adaptive Security Appliance (ASA)Patch soon0.23

Read further