CVE-2019-12698
Summary
| CVE | CVE-2019-12698 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-02 19:15:00 UTC |
| Updated | 2023-08-16 16:17:00 UTC |
| Description | A vulnerability in the WebVPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause increased CPU utilization on an affected device. The vulnerability is due to excessive processing load for a specific WebVPN HTTP page request. An attacker could exploit this vulnerability by sending multiple WebVPN HTTP page load requests for a specific URL. A successful exploit could allow the attacker to increase CPU load on the device, resulting in a denial of service (DoS) condition, which could cause traffic to be delayed through the device. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Adaptive Security Appliance | All | All | All | All |
| Application | Cisco | Adaptive Security Appliance | All | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance Software | All | All | All | All |
| Hardware | Cisco | Asa 5505 | - | All | All | All |
| Hardware | Cisco | Asa 5505 | - | All | All | All |
| Hardware | Cisco | Asa 5510 | - | All | All | All |
| Hardware | Cisco | Asa 5510 | - | All | All | All |
| Hardware | Cisco | Asa 5512-x | - | All | All | All |
| Hardware | Cisco | Asa 5512-x | - | All | All | All |
| Hardware | Cisco | Asa 5515-x | - | All | All | All |
| Hardware | Cisco | Asa 5515-x | - | All | All | All |
| Hardware | Cisco | Asa 5520 | - | All | All | All |
| Hardware | Cisco | Asa 5520 | - | All | All | All |
| Hardware | Cisco | Asa 5525-x | - | All | All | All |
| Hardware | Cisco | Asa 5525-x | - | All | All | All |
| Hardware | Cisco | Asa 5550 | - | All | All | All |
| Hardware | Cisco | Asa 5550 | - | All | All | All |
| Hardware | Cisco | Asa 5555-x | - | All | All | All |
| Hardware | Cisco | Asa 5555-x | - | All | All | All |
| Hardware | Cisco | Asa 5580 | - | All | All | All |
| Hardware | Cisco | Asa 5580 | - | All | All | All |
| Hardware | Cisco | Asa 5585-x | - | All | All | All |
| Hardware | Cisco | Asa 5585-x | - | All | All | All |
| Application | Cisco | Firepower Threat Defense | All | All | All | All |
| Application | Cisco | Firepower Threat Defense | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN CPU Denial of Service Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.