QID 317334

QID 317334: Cisco Adaptive Security Appliance Software Denial of Service (DoS) Vulnerability (cisco-sa-asaftd-ssl-dos-uu7mV5p6)

A vulnerability in the hardware-based SSL/TLS cryptography functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.

Affected Products
Cisco Adaptive Security Appliances if they are running on Cisco Firepower 2100 Series Appliances that are configured for SSL/TLS
From 9.16.4.0 Prior to 9.16.4.14
From 9.18.2.0 Prior to 9.18.2.7

QID Detection Logic (Authenticated):
The check matches Cisco ASA OS version retrieved via Unix Auth using version command

A successful exploit could allow the attacker to cause an unexpected error in the hardware-based cryptography engine, which could cause the device to reload.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-asaftd-ssl-dos-uu7mV5p6 for more information.

    CVEs related to QID 317334

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-asaftd-ssl-dos-uu7mV5p6 URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ssl-dos-uu7mV5p6