CVE-2018-0296
Cisco Adaptive Security Appliance (ASA): Denial-of-Service
As of , CVE-2018-0296 in Cisco Adaptive Security Appliance (ASA) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 3 November 2021
- US federal deadline
- 3 May 2022181 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- Not availableCISA listed it before 4 February 2022, where the EPSS files we read begin.
- Public exploit
- 1 Metasploit module and 2 Exploit-DB entries
- Fix
- No vendor link in CISA's entry
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.
CISA's description
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.
The CVE record's description, from cisco
- CVE published
- 7 June 2018
- Assigned by
- cisco
- CVSS
- 7.5 High (CVSS 3.1, from CISA-ADP)
- CWE-20
- Improper Input Validation
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- partial
Timeline
- The CVE record was published.
- Exploit-DB published an exploit (EDB-ID 44956).
- Exploit-DB published an exploit (EDB-ID 47220).
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: Cisco ASA Directory Traversalauxiliary module, rank normal
- Exploit-DB: Cisco Adaptive Security Appliance - Path Traversal (Metasploit)EDB-ID 47220, 12 August 2019
- Exploit-DB: Cisco Adaptive Security Appliance - Path TraversalEDB-ID 44956, 28 June 2018
Adaptive Security Appliance (ASA): other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2016-6366SNMP Buffer Overflow | Cisco Adaptive Security Appliance (ASA) | Patch this weekMetasploit module; EPSS 0.88 | 0.88 | ||
| CVE-2014-2120Cross-Site Scripting (XSS) | Cisco Adaptive Security Appliance (ASA) | Patch soon | 0.23 | ||
| CVE-2016-6367CLI Remote Code Execution | Cisco Adaptive Security Appliance (ASA) | Patch soon | 0.23 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org