cbcvebase.
CVE-2018-0296
published 2018-06-07

CVE-2018-0296: A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device…

PriorityP187high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.90%
100.0th percentile
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.

Affected

14 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance_software>= 9.1 < 9.1.7.299.1.7.29
ciscoadaptive_security_appliance_software>= 9.2 < 9.2.4.339.2.4.33
ciscoadaptive_security_appliance_software>= 9.3 < 9.4.4.189.4.4.18
ciscoadaptive_security_appliance_software>= 9.5 < 9.6.4.89.6.4.8
ciscoadaptive_security_appliance_software>= 9.7 < 9.7.1.249.7.1.24
ciscoadaptive_security_appliance_software>= 9.8 < 9.8.2.289.8.2.28
ciscoadaptive_security_appliance_software>= 9.9 < 9.9.2.19.9.2.1
ciscoadaptive_security_appliance_web_services
ciscofirepower_threat_defense
ciscofirepower_threat_defense
ciscofirepower_threat_defense
ciscofirepower_threat_defense
ciscofirepower_threat_defense>= 6.0 < 6.1.06.1.0
ciscofirepower_threat_defense>= 6.2.1 < 6.2.2.36.2.2.3

Detection & IOCsextracted from sources · hover to see the quote

snort
46897
  • Run 'show asp table socket | include SSL|DTLS' on the ASA/Firepower device; any listening sockets indicate potential for exploitation.
  • Run 'show processes | include Unicorn' on the ASA/Firepower device; if the Unicorn process is running, the likelihood of vulnerability is elevated.
  • Check Point IPS blade detects exploitation attempts under the signature name 'Cisco Adaptive Security Appliance Web Services Denial of Service'.
  • The exploit involves sending a specially crafted HTTP request containing directory traversal sequences to the ASA/Firepower web interface; monitor HTTP traffic to ASA management interfaces for directory traversal patterns.
  • ·Not all ASA/Firepower appliances are vulnerable; exploitation requires the web framework to be exposed. Only devices with SSL/DTLS listening sockets AND the Unicorn process running are at elevated risk.
  • ·On certain software releases the ASA will not reload (no DoS), but directory traversal for unauthenticated information disclosure is still possible — detection/response posture should account for both outcomes.
  • ·The vulnerability applies to both IPv4 and IPv6 HTTP traffic, so monitoring should cover both protocol families on the management interface.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.