QID 316958

Date Published: 2021-04-30

QID 316958: Cisco Adaptive Security Appliance Software Web Services VPN Denial of Service Vulnerabilities(cisco-sa-asa-ftd-vpn-dos-fpBcpEcD)

Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated,
remote attacker to cause a denial of service (DoS) condition on an affected device.

Affected Products
Cisco devices if they are running a vulnerable release of Cisco ASA Software and
are configured for termination of AnyConnect VPN Client connections. Affected versions:
From 9.7 Prior to 9.8.4.35
From 9.9 Prior to 9.9.2.85
From 9.10 Prior to 9.12.4.10
From 9.13 Prior to 9.13.1.21
From 9.14 Prior to 9.14.2.4
From 9.15 Prior to 9.15.1.7

QID Detection Logic (Authenticated):
The check matches Cisco ASA OS version retrieved via Unix Auth using "version" command.

A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-asa-ftd-vpn-dos-fpBcpEcD for more information.

    CVEs related to QID 316958

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-asa-ftd-vpn-dos-fpBcpEcD URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-vpn-dos-fpBcpEcD