VDB

CISCO-SA-20180418-ASA3

CISCO-SA-20180418-ASA3 PUBLISHED CVSS 8.600000381469727 HIGH

A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a malicious TLS message to an interface enabled for Secure Layer Socket (SSL) services on an affected device. Messages using SSL Version 3 (SSLv3) or SSL Version 2 (SSLv2) cannot be be used to exploit this vulnerability. An exploit could allow the attacker to cause a buffer underflow, triggering a crash on an affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa3 ["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa3"]

Risk Scores

CVSS v3.1
8.600000381469727
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Affected Products

VendorProductVersions
9.2.2
9.2.4.14
9.2.1
9.2.4.10
9.2.4.19
9.2.2.4
9.2.4.16
9.2.3
9.2.4.2
9.2.4.13
9.2.4.17
9.2.4
9.2.4.5
9.2.3.3
9.2.4.8
9.2.3.4
9.2.4.4
9.2.2.8
9.2.4.18
9.2.2.7

Timeline

  • Apr 18, 2018 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›