CVE-2018-0101
published 2018-01-29CVE-2018-0101: A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated…
PriorityP193critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
87.14%
99.7th percentile
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled on the Cisco ASA device. An attacker could exploit this vulnerability by sending multiple, crafted XML packets to a webvpn-configured interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system, or cause a reload of the affected device. This vulnerability affects Cisco ASA Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, ASA 1000V Cloud Firewall, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4110 Security Appliance, Firepower 9300 ASA Security Module, Firepower Threat Defense Software (FTD). Cisco Bug IDs: CSCvg35618.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | < 9.1.7.23 | 9.1.7.23 |
| cisco | adaptive_security_appliance_software | >= 9.2.0 < 9.2.4.27 | 9.2.4.27 |
| cisco | adaptive_security_appliance_software | >= 9.3.0 < 9.4.4.16 | 9.4.4.16 |
| cisco | adaptive_security_appliance_software | >= 9.5.0 < 9.6.4.3 | 9.6.4.3 |
| cisco | adaptive_security_appliance_software | >= 9.7.0 < 9.7.1.21 | 9.7.1.21 |
| cisco | adaptive_security_appliance_software | >= 9.8.0 < 9.8.2.20 | 9.8.2.20 |
| cisco | adaptive_security_appliance_software | >= 9.9.0 < 9.9.1.2 | 9.9.1.2 |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Alert on HTTP POST requests to webvpn interfaces carrying a crafted XML payload body, particularly from clients presenting the AnyConnect user-agent string containing 'gae481214-dirty'. ↗
- →The vulnerability requires SSL services or IKEv2 Remote Access VPN services to be enabled on an interface; monitor for unexpected reloads or VPN authentication request processing failures on ASA devices with these features enabled. ↗
- →The exploit uses IKEv1 fragmentation to deliver the malicious XML payload; monitor for anomalous IKEv1 fragmented traffic directed at ASA interfaces. ↗
- →A denial-of-service proof of concept was published to Pastebin; monitor threat intel feeds and Pastebin for weaponized payloads targeting Cisco ASA webvpn interfaces. ↗
- →Use Nessus Plugin ID 107004 (destructive check, safe checks disabled) to directly confirm DoS exploitability in non-production environments. ↗
- ·The vulnerability is only exploitable when the webvpn feature (SSL VPN) or IKEv2 Remote Access VPN services are enabled on an interface; devices without these features enabled are not vulnerable. ↗
- ·The additional attack vectors added in the February 5, 2018 update (ASDM, CSM, Cut-Through Proxy, Local CA, MDM Proxy, and REST API) may only be vulnerable to denial-of-service, not remote code execution. ↗
- ·The original patch was found to be incomplete; early adopters must apply the updated fixed software versions released after February 5, 2018. ↗
- ·Risk of exploitation also depends on the accessibility of the vulnerable interface to the attacker (internet-facing vs. internal). ↗
CVSS provenance
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability
vendor_cisco·2018-01-29·CVSS 10.0
CVE-2018-0101 [CRITICAL] CWE-415 Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability
Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability
Update from February 5, 2018: After further investigation, Cisco has identified additional attack vectors and features that are affected by this vulnerability. In addition, it was also found that the original fix was incomplete so new fixed code versions are now available. Please see the Fixed Software section for more information.
A vulnerability in the XML parser of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. It was also possible that the ASA could stop processing incoming Virtual Private Network (VPN) authentication requests due to a low memory condition.
The vulnerabili
Cisco
Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0101 Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability
CVE-2018-0101: Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability
Update from February 5, 2018: After further investigation, Cisco has identified additional attack vectors and features that are affected by this vulnerability. In addition, it was also found that the original fix was incomplete so new fixed code versions are now available. Please see the Fixed Software section for more information. A vulnerability in the XML parser of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. It was also possible that the ASA could stop processing incoming Virtual Private Network (VPN) authentication requests due to a low memory condition. The v
GHSA
GHSA-gxj8-6mjh-32m2: A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthentic
ghsa_unreviewed·2022-05-13
CVE-2018-0101 [CRITICAL] CWE-415 GHSA-gxj8-6mjh-32m2: A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthentic
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled on the Cisco ASA device. An attacker could exploit this vulnerability by sending multiple, crafted XML packets to a webvpn-configured interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system, or cause a reload of the affected device. This vulnerability affects Cisco ASA Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (I
VulnCheck
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Double Free
vulncheck·2018·CVSS 10.0
CVE-2018-0101 [CRITICAL] Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Double Free
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Double Free
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled on the Cisco ASA device. An attacker could exploit this vulnerability by sending multiple, crafted XML packets to a webvpn-configured interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system, or cause a reload of the affected device. This vulnerability affects Cisco ASA Software that
No detection rules found.
Talos
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
blogs_talos·2024-04-24·CVSS 9.9
CVE-2025-20333 [CRITICAL] ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
## ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
*Update 2025-09-25: Cisco is aware of new activity targeting certain Cisco Adaptive Security Appliances (ASA) 5500-X Series and has released three CVE’s related to the event: CVE-2025-20333 , CVE-2025-20362 and CVE-2025-20363 . The following Snort Rules cover these vulnerabilities: 65340, 46897.
We assess with high confidence this activity is related to same threat actor as ArcaneDoor in 2024.
We strongly recommend that Cisco customers upgrade their devices to the available fixed software and follow guidance in the security advisories.
*Updated 2024-04-25 16:57 GMT with minor wording corrections regarding the targeting of other vendors. ArcaneDoor is a campaign that is the latest example of state-s
Talos
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
blogs_talos·2024-04-24·CVSS 9.9
CVE-2025-20333 [CRITICAL] ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices
*Update 2025-09-25: Cisco is aware of new activity targeting certain Cisco Adaptive Security Appliances (ASA) 5500-X Series and has released three CVE’s related to the event: CVE-2025-20333, CVE-2025-20362 and CVE-2025-20363. The following Snort Rules cover these vulnerabilities: 65340, 46897.
We assess with high confidence this activity is related to same threat actor as ArcaneDoor in 2024.
We strongly recommend that Cisco customers upgrade their devices to the available fixed software and follow guidance in the security advisories.
*Updated 2024-04-25 16:57 GMT with minor wording corrections regarding the targeting of other vendors.
ArcaneDoor is a campaign that is the latest example of state-sponsored actors targeting perimeter network devices from multiple vendors. Coveted by these
Tenable
Identifying Systems Affected by Cisco ASA Critical Vulnerability (CVE-2018-0101)
blogs_tenable·2018-02-06·CVSS 10.0
CVE-2018-0101 [CRITICAL] Identifying Systems Affected by Cisco ASA Critical Vulnerability (CVE-2018-0101)
Blog / Cyber Exposure Alerts
Subscribe
# Identifying Systems Affected by Cisco ASA Critical Vulnerability (CVE-2018-0101)
Scott Caveza
February 6, 2018
3 Min Read
On January 29, Cisco released an advisory for a critical vulnerability in their Adaptive Security Appliance (ASA) software. The critical flaw, assigned CVE-2018-0101, has a CVSS score of 10.0 and could allow for a denial-of-service attack and remote code execution. On February 5, Cisco updated the advisory indicating they’d found additional attack vectors and more affected products. They also determined the original fix was incomplete. Early adopters of the patch will need to revisit the advisory and apply the latest update to their devices.
### Vulnerability details
The vulnerability was originally found by NCC Group and
Tenable
Identifying Systems Affected by Cisco ASA Critical Vulnerability (CVE-2018-0101)
blogs_tenable·2018-02-06·CVSS 10.0
[CRITICAL] Identifying Systems Affected by Cisco ASA Critical Vulnerability (CVE-2018-0101)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Crowdstrike
Security Advisory: Critical Vulnerability in CredSSP Allows Remote Execution
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Security Advisory: Critical Vulnerability in CredSSP Allows Remote Execution
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
arXiv
Gathering Cyber Threat Intelligence from Twitter Using Novelty Classification
arxiv_fulltext·2019-09-05
Gathering Cyber Threat Intelligence from Twitter Using Novelty Classification
Gathering Cyber Threat Intelligence from Twitter Using Novelty Classification
Ba-Dung Le
School of Computer Science
University of Adelaide
Adelaide, Australia
[email protected]
Guanhua Wang
School of Computer Science
University of Adelaide
Adelaide, Australia
[email protected]
Mehwish Nasim
School of Mathematical Sciences
University of Adelaide
Adelaide, Australia
[email protected]
M. Ali Babar
School of Computer Science
University of Adelaide
Adelaide, Australia
[email protected]
## Abstract
Preventing organizations from Cyber exploits needs timely intelligence about Cyber vulnerabilities and attacks, referred to as threats.
Cyber threat intelligence can be extracted from various sources including social media platforms where users
arXiv
ATTACK2VEC: Leveraging Temporal Word Embeddings to Understand the Evolution of Cyberattacks
arxiv_fulltext·2019-05-29
ATTACK2VEC: Leveraging Temporal Word Embeddings to Understand the Evolution of Cyberattacks
: Leveraging Temporal Word Embeddings to
Understand the Evolution of Cyberattacks
## Abstract
Despite the fact that cyberattacks are constantly growing in complexity, the research community still lacks effective tools to easily monitor and understand them.
In particular, there is a need for techniques that are able to not only track how prominently certain malicious actions, such as the exploitation of specific vulnerabilities, are exploited in the wild, but also (and more importantly) how these malicious actions factor in as attack steps in more complex cyberattacks.
In this paper we present , a system that uses temporal word embeddings to model how attack steps are exploited in the wild, and track how they evolve.
We test on a dataset of billions of security events collected from the c
http://www.securityfocus.com/bid/102845http://www.securitytracker.com/id/1040292https://icanthackit.wordpress.com/2018/01/30/thoughts-on-the-handling-cve-2018-0101-cisco-bug-cscvg35618/https://pastebin.com/YrBcG2Lnhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1https://www.exploit-db.com/exploits/43986/http://www.securityfocus.com/bid/102845http://www.securitytracker.com/id/1040292https://icanthackit.wordpress.com/2018/01/30/thoughts-on-the-handling-cve-2018-0101-cisco-bug-cscvg35618/https://pastebin.com/YrBcG2Lnhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1https://www.exploit-db.com/exploits/43986/
2018-01-29
Published
Exploited in the wild