cbcvebase.
CVE-2018-15454
published 2018-11-01

CVE-2018-15454: A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat…

PriorityP275high8.6CVSS 3.0
AVNACLPRNUINSCCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
4.38%
90.2th percentile
A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of SIP traffic. An attacker could exploit this vulnerability by sending SIP requests designed to specifically trigger this issue at a high rate across an affected device. Software updates that address this vulnerability are not yet available.

Affected

11 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance
ciscoadaptive_security_appliance_software>= 9.10 < 9.10.1.29.10.1.2
ciscoadaptive_security_appliance_software>= 9.4 < 9.4.4.279.4.4.27
ciscoadaptive_security_appliance_software>= 9.6 < 9.6.4.189.6.4.18
ciscoadaptive_security_appliance_software>= 9.8 < 9.8.3.169.8.3.16
ciscoadaptive_security_appliance_software>= 9.9 < 9.9.2.329.9.2.32
ciscocisco_adaptive_security_appliance_software
ciscofirepower_threat_defense>= 6.1.0 < 6.1.0.76.1.0.7
ciscofirepower_threat_defense>= 6.2.0 < 6.2.0.66.2.0.6
ciscofirepower_threat_defense>= 6.2.2 < 6.2.2.46.2.2.4
ciscofirepower_threat_defense>= 6.2.3 < 6.2.3.76.2.3.7

Detection & IOCsextracted from sources · hover to see the quote

port5060
  • Monitor for high-rate SIP request floods traversing Cisco ASA or FTD devices — sustained high CPU or repeated device reloads may indicate active exploitation of the SIP inspection engine.
  • Alert on abnormal CPU spikes or unexpected reloads on Cisco ASA/FTD appliances that have SIP inspection enabled, as these are the primary observable symptoms of exploitation.
  • Track Cisco bug ID CSCvm43975 for vendor patch and detection signature updates related to this vulnerability.
  • ·The vulnerability is specifically in the SIP inspection engine; devices with SIP inspection disabled are not affected. Mitigation (not a full workaround) may involve disabling or restricting SIP inspection on affected ASA/FTD devices.
  • ·The vulnerability is triggered by improper handling of SIP traffic in the inspection engine — only traffic passing through the SIP inspection policy on the device is a viable attack vector.

CVSS provenance

nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck8.6HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.