CISCO-SA-20180418-ASA3
A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a malicious TLS message to an interface enabled for Secure Layer Socket (SSL) services on an affected device. Messages using SSL Version 3 (SSLv3) or SSL Version 2 (SSLv2) cannot be be used to exploit this vulnerability. An exploit could allow the attacker to cause a buffer underflow, triggering a crash on an affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa3 ["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa3"]
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 9.2.2 | ||
| 9.2.4.14 | ||
| 9.2.1 | ||
| 9.2.4.10 | ||
| 9.2.4.19 | ||
| 9.2.2.4 | ||
| 9.2.4.16 | ||
| 9.2.3 | ||
| 9.2.4.2 | ||
| 9.2.4.13 | ||
| 9.2.4.17 | ||
| 9.2.4 | ||
| 9.2.4.5 | ||
| 9.2.3.3 | ||
| 9.2.4.8 | ||
| 9.2.3.4 | ||
| 9.2.4.4 | ||
| 9.2.2.8 | ||
| 9.2.4.18 | ||
| 9.2.2.7 |
Timeline
- Apr 18, 2018 CVE Published
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa3 advisory
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html url
- https://www.cisco.com/c/en/us/products/end-user-license-agreement.html url
- https://www.cisco.com/go/psirt url
- https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html url
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa1 url
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2018418-asa2 url
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asaanyconnect url
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa_inspect url
- https://software.cisco.com/download/navigator.html url
- https://software.cisco.com fix