—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1
Cisco Security Advisory: Cisco Adaptive Security Appliance Application Layer Protocol Inspection Denial of Service Vulnerabilities
Advisory ID: cisco-sa-20180418-asa_inspect
Revision: 1.0
For Public Release: 2018 April 18 16:00 GMT
Last Updated: 2018 April 18 16:00 GMT
CVE ID(s): CVE-2018-0240
CVSS Score v(3): 8.6 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
+———————————————————————
Summary
=======
Multiple vulnerabilities in the Application Layer Protocol Inspection feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
The vulnerabilities are due to logical errors during traffic inspection. An attacker could exploit these vulnerabilities by sending a high volume of malicious traffic across an affected device. An exploit could allow the attacker to cause a deadlock condition, resulting in a reload of an affected device.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa_inspect [“https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa_inspect”]
—–BEGIN PGP SIGNATURE—–
iQJ5BAEBAgBjBQJa128FXBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50
IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly
dEBjaXNjby5jb20+AAoJEJa12PPJBfczQu8QALGOWI5hTwWQufyKIJ+sNjqSIWLN
Cj/fK+Xq4fgcDE9PApJ+XKT+zJoKok3oOBYmtUJbj9RlotKJhDk7+lGK+1M9vuuN
jbT+TBzpIGBngfIA4Nl8LQsf6UAdRq2ZFk70MBttfXVwWConOmhYKggbY0zUq/xe
v85xVVdgmd0We0Zfbg6MsoLxMpJ3qBWyVX1F/XU2g9rJa+kL1hjlXqkynrbFW+ed
8ecyInzqiYN1vyTZeLH42nItJAxmuNuLTIg69vkZ5LYanKdBBBmuAsVGBIAKv6PF
aKs9FhRyjo+JNNRuoG7qNtU8yTgIj4SrNEnWShrunhUxMIZcHpVTfPCV7b0kMpLS
YDlY84rS3fTj6ocdzPtW4dy9r2/tbmDGUo3Tw6N2DuC64QLkeYFPLW8FWBqjOtaA
eGzRxgTLyT8E0fOGgxjplVzxHaDlARbs104YIHYdDorzhejh4Tdux6dQpHhaaxE1
ZbeJgSm4mw5QBOR+lLW8s81mtbpsAX36SHkFJXRWJ6sV2SF1s5yFSCtdnTUKwVTc
koPmNI7L5F7nGIDaFYgFz+jV67i7ztT8IULmzr+HO+fxRsmutw9c6Nu8WWbe+lRz
XjGDggJmT24Bj1vosbJZ6k+nb0FjDBxQ7og62YOTKsqqVv0iUjV4ZDFb5XHf+Hwh
ReeQipRHqQUU6UiN
=o5aj
—–END PGP SIGNATURE—–
_______________________________________________
cust-security-announce mailing list
cust-security-announce@cisco.com
To unsubscribe, send the command “unsubscribe” in the subject of your message to cust-security-announce-leave@cisco.com