CVE-2018-15383Uncontrolled Resource Consumption in Cisco Adaptive Security Appliance Software

Severity
7.5HIGHNVD
EPSS
0.9%
top 23.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 5
Latest updateMay 13

Description

A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a temporary denial of service (DoS) condition. The vulnerability exists because the affected devices have a limited amount of Direct Memory Access (DMA) memory and the affected software improperly handles resources in low-memory cond

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-hmv9-9gm3-c2vc: A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defens2022-05-13
CVEList
Cisco Adaptive Security Appliance Direct Memory Access Denial of Service Vulnerability2018-10-05

📋Vendor Advisories

1
Cisco
Cisco Adaptive Security Appliance Direct Memory Access Denial of Service Vulnerability2018-10-03
CVE-2018-15383 — Uncontrolled Resource Consumption | cvebase