Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software Denial of Service Vulnerability
Published Nov 1, 2018
8.6
HIGHCVSS 3.0
EPSS 4.38%
Description
A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of SIP traffic. An attacker could exploit this vulnerability by sending SIP requests designed to specifically trigger this issue at a high rate across an affected device. Software updates that address this vulnerability are not yet available.
Affected products
-
- Version 9.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Cisco | Cisco Adaptive Security Appliance (ASA) Software | n/a |
|
Configuration 1
- ≥ 9.4 · < 9.4.4.27
- ≥ 9.6 · < 9.6.4.18
- ≥ 9.8 · < 9.8.3.16
- ≥ 9.9 · < 9.9.2.32
- ≥ 9.10 · < 9.10.1.2
Configuration 2
- ≥ 6.1.0 · < 6.1.0.7
- ≥ 6.2.0 · < 6.2.0.6
- ≥ 6.2.2 · < 6.2.2.4
- ≥ 6.2.3 · < 6.2.3.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- http://www.securityfocus.com/bid/105768 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1042129 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-7332 Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181031-asaftd-sip-dos vendor-advisoryx_refsource_CISCOMitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/105768 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1042129 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-7332 | Advisory | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181031-asaftd-sip-dos | vendor-advisoryx_refsource_CISCOMitigationVendor Advisory |
Change history (0)
No recorded changes yet.