cbcvebase.
CVE-2018-0101
published 2018-01-29

CVE-2018-0101: A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated…

PriorityP193critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
87.14%
99.7th percentile
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled on the Cisco ASA device. An attacker could exploit this vulnerability by sending multiple, crafted XML packets to a webvpn-configured interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system, or cause a reload of the affected device. This vulnerability affects Cisco ASA Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, ASA 1000V Cloud Firewall, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4110 Security Appliance, Firepower 9300 ASA Security Module, Firepower Threat Defense Software (FTD). Cisco Bug IDs: CSCvg35618.

Affected

14 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance
ciscoadaptive_security_appliance_software< 9.1.7.239.1.7.23
ciscoadaptive_security_appliance_software>= 9.2.0 < 9.2.4.279.2.4.27
ciscoadaptive_security_appliance_software>= 9.3.0 < 9.4.4.169.4.4.16
ciscoadaptive_security_appliance_software>= 9.5.0 < 9.6.4.39.6.4.3
ciscoadaptive_security_appliance_software>= 9.7.0 < 9.7.1.219.7.1.21
ciscoadaptive_security_appliance_software>= 9.8.0 < 9.8.2.209.8.2.20
ciscoadaptive_security_appliance_software>= 9.9.0 < 9.9.1.29.9.1.2
ciscofirepower_threat_defense
ciscofirepower_threat_defense
ciscofirepower_threat_defense
ciscofirepower_threat_defense
ciscofirepower_threat_defense
ciscofirepower_threat_defense

Detection & IOCsextracted from sources · hover to see the quote

uaOpen AnyConnect VPN Agent v7.08-265-gae481214-dirty
otherX-Aggregate-Auth: 1
otherX-Transcend-Version: 1
otherX-AnyConnect-Platform: linux-64
otherX-Support-HTTP-Auth: false
  • Alert on HTTP POST requests to webvpn interfaces carrying a crafted XML payload body, particularly from clients presenting the AnyConnect user-agent string containing 'gae481214-dirty'.
  • The vulnerability requires SSL services or IKEv2 Remote Access VPN services to be enabled on an interface; monitor for unexpected reloads or VPN authentication request processing failures on ASA devices with these features enabled.
  • The exploit uses IKEv1 fragmentation to deliver the malicious XML payload; monitor for anomalous IKEv1 fragmented traffic directed at ASA interfaces.
  • A denial-of-service proof of concept was published to Pastebin; monitor threat intel feeds and Pastebin for weaponized payloads targeting Cisco ASA webvpn interfaces.
  • Use Nessus Plugin ID 107004 (destructive check, safe checks disabled) to directly confirm DoS exploitability in non-production environments.
  • ·The vulnerability is only exploitable when the webvpn feature (SSL VPN) or IKEv2 Remote Access VPN services are enabled on an interface; devices without these features enabled are not vulnerable.
  • ·The additional attack vectors added in the February 5, 2018 update (ASDM, CSM, Cut-Through Proxy, Local CA, MDM Proxy, and REST API) may only be vulnerable to denial-of-service, not remote code execution.
  • ·The original patch was found to be incomplete; early adopters must apply the updated fixed software versions released after February 5, 2018.
  • ·Risk of exploitation also depends on the accessibility of the vulnerable interface to the attacker (internet-facing vs. internal).

CVSS provenance

nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.