cbcvebase.
CVE-2017-3807
published 2017-02-09

CVE-2017-3807: A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an…

PriorityP269high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
14.76%
96.3th percentile
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remote attacker to cause a heap overflow. The vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by sending a crafted URL to the affected system. An exploit could allow the remote attacker to cause a reload of the affected system or potentially execute code. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability affects systems configured in routed firewall mode only and in single or multiple context mode. This vulnerability can be triggered by IPv4 or IPv6 traffic. A valid TCP connection is needed to perform the attack. The attacker needs to have valid credentials to log in to the Clientless SSL VPN portal. Vulnerable Cisco ASA Software running on the following products may be affected by this vulnerability: Cisco ASA 5500 Series Adaptive Security Appliances, Cisco ASA 5500-X Series Next-Generation Firewalls, Cisco Adaptive Security Virtual Appliance (ASAv), Cisco ASA for Firepower 9300 Series, Cisco ASA for Firepower 4100 Series. Cisco Bug IDs: CSCvc23838.

Affected

325 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://portal/+webvpn+/CIFS_R/server/name/<500 'A's>
path/+webvpn+/CIFS_R/
processlina
  • Detect HTTP GET requests to the Cisco ASA WebVPN portal containing the '/+webvpn+/CIFS_R/' URL path prefix with an unusually long path component (>336 bytes) — indicative of the heap overflow exploit attempt.
  • Monitor for heap corruption crashes in the 'lina' process on Cisco ASA devices, specifically malloc memory corruption errors, as a post-exploitation indicator of CVE-2017-3807 triggering.
  • The exploit requires a valid authenticated session to the Clientless SSL VPN portal; correlate WebVPN login events immediately followed by CIFS_R path requests with oversized path components from the same session.
  • ·Vulnerability only affects Cisco ASA devices configured in routed firewall mode (not transparent mode); single or multiple context mode are both affected.
  • ·The Clientless SSL VPN (WebVPN) feature must be enabled and accessible for this vulnerability to be exploitable; disabling WebVPN mitigates the attack surface.
  • ·Exploitation requires valid credentials to the WebVPN portal; unauthenticated attackers cannot trigger this vulnerability.
  • ·The CIFS share referenced in the exploit URL does not need to actually exist on the network for the vulnerability to be triggered.
  • ·Affected ASA major releases are 9.0 through 9.6; the PoC was specifically tested on version 9.6(2).

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.0HIGHAV:N/AC:L/Au:S/C:P/I:P/A:C
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.