Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software MOBIKE Denial of Service Vulnerability
Summary
| CVE | CVE-2019-1708 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-03 16:29:00 UTC |
| Updated | 2026-08-11 19:33:44 UTC |
| Description | A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to the incorrect processing of certain MOBIKE packets. An attacker could exploit this vulnerability by sending crafted MOBIKE packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. The MOBIKE feature is supported only for IPv4 addresses. |
Risk And Classification
Primary CVSS: v3.1 8.6 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS: 0.020390000 probability, percentile 0.793690000 (date 2026-08-12)
Problem Types: CWE-404 | CWE-401 | CWE-404 CWE-404
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 8.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
| 3.0 | [email protected] | Secondary | 8.6 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
| 3.0 | CNA | DECLARED | 8.6 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 7.8 | AV:N/AC:L/Au:N/C:N/I:N/A:C |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Adaptive Security Appliance Software | All | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance Software | All | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance Software | All | All | All | All |
| Hardware | Cisco | Asa-5506-x | - | All | All | All |
| Hardware | Cisco | Asa-5525-x | - | All | All | All |
| Hardware | Cisco | Asa-5555-x | - | All | All | All |
| Hardware | Cisco | Asa 5506h-x | - | All | All | All |
| Hardware | Cisco | Asa 5506w-x | - | All | All | All |
| Hardware | Cisco | Asa 5508-x | - | All | All | All |
| Hardware | Cisco | Asa 5516-x | - | All | All | All |
| Hardware | Cisco | Asa 5545-x | - | All | All | All |
| Application | Cisco | Secure Firewall Threat Defense | All | All | All | All |
| Application | Cisco | Secure Firewall Threat Defense | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Cisco | Cisco Adaptive Security Appliance ASA Software | affected unspecified 9.8.4 custom | Not specified |
| CNA | Cisco | Cisco Adaptive Security Appliance ASA Software | affected unspecified 9.9.2.50 custom | Not specified |
| CNA | Cisco | Cisco Adaptive Security Appliance ASA Software | affected unspecified 9.10.1.17 custom | Not specified |
| CNA | Cisco | Cisco Firepower Threat Defense FTD Software | affected unspecified 6.2.3.12 custom | Not specified |
| CNA | Cisco | Cisco Firepower Threat Defense FTD Software | affected unspecified 6.3.0.3 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software MOBIKE Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| Multiple Cisco Products CVE-2019-1708 Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Exploits
CNA: The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
There are currently no legacy QID mappings associated with this CVE.