QID 316960
Date Published: 2021-04-30
QID 316960: Cisco Adaptive Security Appliance Software SIP Denial of Service Vulnerability(cisco-sa-asa-ftd-sipdos-GGwmMerC)
A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software
could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device,
resulting in a denial of service (DoS) condition.
Affected Products
Cisco products if they are running a vulnerable release of Cisco ASA Software or FTD Software and have SIP inspection configured.
From 9.8 Prior to 9.8.4.34
From 9.9 Prior to 9.9.2.85
From 9.10 Prior to 9.12.4.18
From 9.13 Prior to 9.13.1.21
From 9.14 Prior to 9.14.2.13
From 9.15 Prior to 9.15.1.15
Note: SIP inspection is enabled by default on Cisco ASA Software.
QID Detection Logic (Authenticated):
The check matches Cisco ASA OS version retrieved via Unix Auth using "version" command.
A successful exploit could allow the attacker to cause a crash and reload of the affected device.
Customers are advised to refer to cisco-sa-asa-ftd-sipdos-GGwmMerC for more information.Workaround:
There are no workarounds that address this vulnerability. However, there are mitigation options that apply to both physical and virtual appliances.
i. Disable SIP Inspection
ii. Allow Only Trusted SIP Hosts Using ACLs
- cisco-sa-asa-ftd-sipdos-GGwmMerC -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-sipdos-GGwmMerC
CVEs related to QID 316960
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-asa-ftd-sipdos-GGwmMerC |
|