Cisco investigation reveals ASA vulnerability is worse than originally thought
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-0101 | A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remo A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled on the Cisco ASA device. An attacker could exploit this vulnerability by sending multiple, crafted XML packets to a webvpn-configured interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system, or cause a reload of the affected device. This vulnerability affects Cisco ASA Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, ASA 1000V Cloud Firewall, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4110 Security Appliance, Firepower 9300 ASA Security Module, Firepower Threat Defense Software (FTD). Cisco Bug IDs: CSCvg35618. NVD description · AI analysis pending | 10.0 | 87% | PoC ×2 |
| — |
Full article313 words · extracted from cyberscoop.com · click to collapse
The second look revealed additional attack vectors and raised the ire of IT staffs everywhere.
The “perfect 10.0” critical vulnerability Cisco announced last week in its Adaptive Security Appliance (ASA) devices has additional attack vectors and affects more features that originally thought, the company said.
A company investigation revealed the original response did not identify or fix the entire problem, so a new patch for Cisco ASA platforms is now available. This means Cisco customers will have additional downtime for security maintenance in order to fix a bug that potentially allows an unauthenticated, remote attacker to execute code and cause system reloads.
The problem is raising small hell on social media from systems and network administrators about additional downtime.
Heads up: Cisco just updated the advisory on CVE-2018-0101 (ASA webvpn / AnyConnect RCE) with a newer software release to fix additional exploitation vectors not covered in last week's patch. https://t.co/onwRSoXAla
— David Longenecker (@dnlongen) February 5, 2018
All currently recommended ASA Software versions to fix CVE-2018-0101 were published 2 days ago on Feb 3. If you patched last week, you need to patch again.
— Colin (@EdwardsCP) February 5, 2018
“After broadening the investigation, Cisco engineers found other attack vectors and features that are affected by this vulnerability that were not originally identified by the NCC Group and subsequently updated the security advisory,” Cisco’s Omar Santos wrote. “In addition, it was also found that the original list of fixed releases published in the security advisory were later found to be vulnerable to additional denial of service conditions. A new comprehensive fix for Cisco ASA platforms is now available.”
The impacted Cisco products are tools for protecting corporate networks and data centers. There have been no reports of exploitation but Cisco urges customers to patch quickly.
You can find technical details of the bug here.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cisco-asa-vulnerability-worse-than-thought/