QID 317185

Date Published: 2022-05-12

QID 317185: Cisco Adaptive Security Appliance (ASA) Software Web Services Interface Denial of Service (DoS) Vulnerability (cisco-sa-asafdt-webvpn-dos-tzPSYern)

A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. Affected Products
his vulnerability affects Cisco products if they are running a vulnerable release of Cisco ASA Software or Cisco FTD Software with a vulnerable remote access VPN configuration.

QID Detection Logic (Authenticated):
The check matches Cisco ASA OS version retrieved via Unix Auth using "version" command.

An attacker could exploit this vulnerability by sending a crafted HTTPS request to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition..

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-asafdt-webvpn-dos-tzPSYern for more information.

    CVEs related to QID 317185

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-asafdt-webvpn-dos-tzPSYern URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asafdt-webvpn-dos-tzPSYern