CVE-2018-0240
published 2018-04-19CVE-2018-0240: Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat…
PriorityP350high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
3.86%
89.1th percentile
Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerabilities are due to logical errors during traffic inspection. An attacker could exploit these vulnerabilities by sending a high volume of malicious traffic across an affected device. An exploit could allow the attacker to cause a deadlock condition, resulting in a reload of an affected device. These vulnerabilities affect Cisco ASA Software and Cisco FTD Software configured for Application Layer Protocol Inspection running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCve61540, CSCvh23085, CSCvh95456.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_application_layer_protocol_inspection | — | — |
| cisco | adaptive_security_appliance_software | >= 9.6.0.0 < 9.6.4.6 | 9.6.4.6 |
| cisco | adaptive_security_appliance_software | >= 9.7.0.0 < 9.7.1.24 | 9.7.1.24 |
| cisco | adaptive_security_appliance_software | >= 9.8.0.0 < 9.8.2.24 | 9.8.2.24 |
| cisco | adaptive_security_appliance_software | >= 9.9.0.0 < 9.9.1.4 | 9.9.1.4 |
| cisco | firepower_threat_defense | 6.1.0 – 6.1.0.7 | — |
| cisco | firepower_threat_defense | >= 6.2.0 < 6.2.0.5 | 6.2.0.5 |
| cisco | firepower_threat_defense | >= 6.2.1 < 6.2.2.2 | 6.2.2.2 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Allen-Bradley Stratix 5950
cisa_ics·2018-07-03·CVSS 8.6
[HIGH] Rockwell Automation Allen-Bradley Stratix 5950
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Allen-Bradley Stratix 5950
Last RevisedJuly 03, 2018
Alert CodeICSA-18-184-01
## 1. EXECUTIVE SUMMARY
-
CVSS v3 8.6
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix 5950
- Vulnerabilities: Improper Input Validation, Improper Certificate Validation, Resource Management Errors
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to bypass client certification to create connections to the affected device or cause the device to crash.
## 3
Cisco
Cisco Adaptive Security Appliance Application Layer Protocol Inspection Denial of Service Vulnerabilities
vendor_cisco·2018-04-18·CVSS 8.6
CVE-2018-0240 [HIGH] CWE-399 Cisco Adaptive Security Appliance Application Layer Protocol Inspection Denial of Service Vulnerabilities
Cisco Adaptive Security Appliance Application Layer Protocol Inspection Denial of Service Vulnerabilities
Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
The vulnerabilities are due to logical errors during traffic inspection. An attacker could exploit these vulnerabilities by sending a high volume of malicious traffic across an affected device. An exploit could allow the attacker to cause a deadlock condition, resulting in a reload of an affected device.
Cisco has released software updates that address these vulnerabi
Cisco
Cisco Adaptive Security Appliance Application Layer Protocol Inspection Denial of Service Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2018-0240 Cisco Adaptive Security Appliance Application Layer Protocol Inspection Denial of Service Vulnerabilities
CVE-2018-0240: Cisco Adaptive Security Appliance Application Layer Protocol Inspection Denial of Service Vulnerabilities
Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerabilities are due to logical errors during traffic inspection. An attacker could exploit these vulnerabilities by sending a high volume of malicious traffic across an affected device. An exploit could allow the attacker to cause a deadlock condition, resulting in a reload of an affected device. Cisco has released software updates that address the
GHSA
GHSA-c4wx-x65q-h4fx: Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower
ghsa_unreviewed·2022-05-13
CVE-2018-0240 [HIGH] GHSA-c4wx-x65q-h4fx: Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower
Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerabilities are due to logical errors during traffic inspection. An attacker could exploit these vulnerabilities by sending a high volume of malicious traffic across an affected device. An exploit could allow the attacker to cause a deadlock condition, resulting in a reload of an affected device. These vulnerabilities affect Cisco ASA Software and Cisco FTD Software configured for Application Layer Protocol Inspection running on the following Cisco products: 3000 Ser
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/103934http://www.securitytracker.com/id/1040722https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa_inspecthttp://www.securityfocus.com/bid/103934http://www.securitytracker.com/id/1040722https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa_inspect
2018-04-19
Published