CVE-2018-0227
published 2018-04-19CVE-2018-0227: A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.05%
79.2th percentile
A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps. The vulnerability is due to incorrect verification of the SSL Client Certificate. An attacker could exploit this vulnerability by connecting to the ASA VPN without a proper private key and certificate pair. A successful exploit could allow the attacker to establish an SSL VPN connection to the ASA when the connection should have been rejected. This vulnerability affects Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliances (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliances (ASAv), Firepower 4110 Security Appliances, Firepower 9300 ASA Security Modules. Cisco Bug IDs: CSCvg40155.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | 9.4.4 – 9.4.4.13 | — |
| cisco | adaptive_security_appliance_software | 9.5.3.7 – 9.5.3.9 | — |
| cisco | adaptive_security_appliance_software | 9.6.2.9 – 9.6.2.21 | — |
| cisco | adaptive_security_appliance_software | 9.6.3 – 9.6.3.17 | — |
| cisco | adaptive_security_appliance_virtual_private_network_ssl | — | — |
| cisco | firepower_threat_defense | 6.0 – 6.0.1.4 | — |
| cisco | firepower_threat_defense | 6.1.0 – 6.1.0.5 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-25vq-3gfh-mvj7: A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security
ghsa_unreviewed·2022-05-13
CVE-2018-0227 [HIGH] CWE-295 GHSA-25vq-3gfh-mvj7: A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security
A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps. The vulnerability is due to incorrect verification of the SSL Client Certificate. An attacker could exploit this vulnerability by connecting to the ASA VPN without a proper private key and certificate pair. A successful exploit could allow the attacker to establish an SSL VPN connection to the ASA when the connection should have been rejected. This vulnerability affects Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Software that is running on the following Cisco
CISA ICS
Rockwell Automation Allen-Bradley Stratix 5950
cisa_ics·2018-07-03·CVSS 8.6
[HIGH] Rockwell Automation Allen-Bradley Stratix 5950
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Allen-Bradley Stratix 5950
Last RevisedJuly 03, 2018
Alert CodeICSA-18-184-01
## 1. EXECUTIVE SUMMARY
-
CVSS v3 8.6
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix 5950
- Vulnerabilities: Improper Input Validation, Improper Certificate Validation, Resource Management Errors
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to bypass client certification to create connections to the affected device or cause the device to crash.
## 3
Cisco
Cisco Adaptive Security Appliance Virtual Private Network SSL Client Certificate Bypass Vulnerability
vendor_cisco·2018-04-18·CVSS 7.5
CVE-2018-0227 [HIGH] CWE-295 Cisco Adaptive Security Appliance Virtual Private Network SSL Client Certificate Bypass Vulnerability
Cisco Adaptive Security Appliance Virtual Private Network SSL Client Certificate Bypass Vulnerability
A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps.
The vulnerability is due to incorrect verification of the SSL Client Certificate. An attacker could exploit this vulnerability by connecting to the ASA VPN without a proper private key and certificate pair. A successful exploit could allow the attacker to establish an SSL VPN connection to the ASA when the connection should have been rejected.
Cisco has released software updates that addr
Cisco
Cisco Adaptive Security Appliance Virtual Private Network SSL Client Certificate Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0227 Cisco Adaptive Security Appliance Virtual Private Network SSL Client Certificate Bypass Vulnerability
CVE-2018-0227: Cisco Adaptive Security Appliance Virtual Private Network SSL Client Certificate Bypass Vulnerability
A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps. The vulnerability is due to incorrect verification of the SSL Client Certificate. An attacker could exploit this vulnerability by connecting to the ASA VPN without a proper private key and certificate pair. A successful exploit could allow the attacker to establish an SSL VPN connection to the ASA when the connection should have been rejected. Cisco has released software updat
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/104018http://www.securitytracker.com/id/1040723https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa1http://www.securityfocus.com/bid/104018http://www.securitytracker.com/id/1040723https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa1
2018-04-19
Published