CVE-2017-3807
published 2017-02-09CVE-2017-3807: A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an…
PriorityP269high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
14.76%
96.3th percentile
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remote attacker to cause a heap overflow. The vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by sending a crafted URL to the affected system. An exploit could allow the remote attacker to cause a reload of the affected system or potentially execute code. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability affects systems configured in routed firewall mode only and in single or multiple context mode. This vulnerability can be triggered by IPv4 or IPv6 traffic. A valid TCP connection is needed to perform the attack. The attacker needs to have valid credentials to log in to the Clientless SSL VPN portal. Vulnerable Cisco ASA Software running on the following products may be affected by this vulnerability: Cisco ASA 5500 Series Adaptive Security Appliances, Cisco ASA 5500-X Series Next-Generation Firewalls, Cisco Adaptive Security Virtual Appliance (ASAv), Cisco ASA for Firepower 9300 Series, Cisco ASA for Firepower 4100 Series. Cisco Bug IDs: CSCvc23838.
Affected
325 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP GET requests to the Cisco ASA WebVPN portal containing the '/+webvpn+/CIFS_R/' URL path prefix with an unusually long path component (>336 bytes) — indicative of the heap overflow exploit attempt. ↗
- →Monitor for heap corruption crashes in the 'lina' process on Cisco ASA devices, specifically malloc memory corruption errors, as a post-exploitation indicator of CVE-2017-3807 triggering. ↗
- →The exploit requires a valid authenticated session to the Clientless SSL VPN portal; correlate WebVPN login events immediately followed by CIFS_R path requests with oversized path components from the same session. ↗
- ·Vulnerability only affects Cisco ASA devices configured in routed firewall mode (not transparent mode); single or multiple context mode are both affected. ↗
- ·The Clientless SSL VPN (WebVPN) feature must be enabled and accessible for this vulnerability to be exploitable; disabling WebVPN mitigates the attack surface. ↗
- ·Exploitation requires valid credentials to the WebVPN portal; unauthenticated attackers cannot trigger this vulnerability. ↗
- ·The CIFS share referenced in the exploit URL does not need to actually exist on the network for the vulnerability to be triggered. ↗
- ·Affected ASA major releases are 9.0 through 9.6; the PoC was specifically tested on version 9.6(2). ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.0HIGHAV:N/AC:L/Au:S/C:P/I:P/A:C
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-77g6-4h48-g6wv: A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9
ghsa_unreviewed·2022-05-14
CVE-2017-3807 [HIGH] CWE-119 GHSA-77g6-4h48-g6wv: A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remote attacker to cause a heap overflow. The vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by sending a crafted URL to the affected system. An exploit could allow the remote attacker to cause a reload of the affected system or potentially execute code. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability affects systems configured in routed firewall mode only and in single or multiple context mode. This vulnerability can be triggered by IPv4 or IPv6 traffic. A valid TCP connection is need
Cisco
Cisco ASA Clientless SSL VPN CIFS Heap Overflow Vulnerability
vendor_cisco·2017-02-08·CVSS 8.8
CVE-2017-3807 [HIGH] CWE-119 Cisco ASA Clientless SSL VPN CIFS Heap Overflow Vulnerability
Cisco ASA Clientless SSL VPN CIFS Heap Overflow Vulnerability
A vulnerability in Common Internet Filesystem (CIFS) code in the
Clientless SSL VPN functionality of Cisco ASA Software could allow an
authenticated, remote attacker to cause a heap overflow.
The
vulnerability is due to insufficient validation of user supplied input. An attacker could
exploit this vulnerability by sending a crafted URL to the affected
system. An exploit could allow the remote attacker to cause a reload of the
affected system or potentially execute code.
Note: Only traffic directed to the affected system can
be used to exploit this vulnerability. This vulnerability affects
systems configured in routed firewall mode only and in single or
multiple context mode. This vulnerability can be triggered by IPv4 or
IPv6
Cisco
Cisco ASA Clientless SSL VPN CIFS Heap Overflow Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3807 Cisco ASA Clientless SSL VPN CIFS Heap Overflow Vulnerability
CVE-2017-3807: Cisco ASA Clientless SSL VPN CIFS Heap Overflow Vulnerability
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software could allow an authenticated, remote attacker to cause a heap overflow. The vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by sending a crafted URL to the affected system. An exploit could allow the remote attacker to cause a reload of the affected system or potentially execute code. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability affects systems configured in routed firewall mode only and in single or multiple context mode. This vulnerability can be triggered by
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/96161http://www.securitytracker.com/id/1037797https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170208-asahttps://www.exploit-db.com/exploits/41369/http://www.securityfocus.com/bid/96161http://www.securitytracker.com/id/1037797https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170208-asahttps://www.exploit-db.com/exploits/41369/
2017-02-09
Published