CVE-2019-1693
Summary
| CVE | CVE-2019-1693 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-03 15:29:00 UTC |
| Updated | 2023-08-15 15:24:00 UTC |
| Description | A vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper management of authenticated sessions in the WebVPN portal. An attacker could exploit this vulnerability by authenticating with valid credentials and accessing a specific URL in the WebVPN portal. A successful exploit could allow the attacker to cause the device to reload, resulting in a temporary DoS condition. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Adaptive Security Appliance Software | All | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance Software | All | All | All | All |
| Application | Cisco | Adaptive Security Appliance Software | All | All | All | All |
| Hardware | Cisco | Asa 5505 | - | All | All | All |
| Hardware | Cisco | Asa 5505 | - | All | All | All |
| Hardware | Cisco | Asa 5510 | - | All | All | All |
| Hardware | Cisco | Asa 5510 | - | All | All | All |
| Hardware | Cisco | Asa 5512-x | - | All | All | All |
| Hardware | Cisco | Asa 5512-x | - | All | All | All |
| Hardware | Cisco | Asa 5515-x | - | All | All | All |
| Hardware | Cisco | Asa 5515-x | - | All | All | All |
| Hardware | Cisco | Asa 5520 | - | All | All | All |
| Hardware | Cisco | Asa 5520 | - | All | All | All |
| Hardware | Cisco | Asa 5525-x | - | All | All | All |
| Hardware | Cisco | Asa 5525-x | - | All | All | All |
| Hardware | Cisco | Asa 5540 | - | All | All | All |
| Hardware | Cisco | Asa 5540 | - | All | All | All |
| Hardware | Cisco | Asa 5545-x | - | All | All | All |
| Hardware | Cisco | Asa 5545-x | - | All | All | All |
| Hardware | Cisco | Asa 5550 | - | All | All | All |
| Hardware | Cisco | Asa 5550 | - | All | All | All |
| Hardware | Cisco | Asa 5555-x | - | All | All | All |
| Hardware | Cisco | Asa 5555-x | - | All | All | All |
| Hardware | Cisco | Asa 5580 | - | All | All | All |
| Hardware | Cisco | Asa 5580 | - | All | All | All |
| Hardware | Cisco | Asa 5585-x | - | All | All | All |
| Hardware | Cisco | Asa 5585-x | - | All | All | All |
| Application | Cisco | Firepower Threat Defense | All | All | All | All |
| Application | Cisco | Firepower Threat Defense | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Cisco Products CVE-2019-1693 Denial of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN Denial of Service Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.