QID 317379
QID 317379: Cisco Firepower Threat Defense (FTD) Remote Access Virtual Private Network (VPN) Denial of Service (DoS) Vulnerability (cisco-sa-asa-webvpn-dos-3GhZQBAS)
This vulnerability is due to improper handling of HTTPS requests. An attacker could exploit this vulnerability by sending crafted HTTPS requests to an affected system.
Affected Products
This vulnerability affects Cisco products if they are running a vulnerable release of Cisco FTD Software when it has Cisco AnyConnect Remote Access VPN enabled.
Cisco FTD Software version from 6.2.3 prior to 6.4.0.16
Cisco FTD Software version from 6.6.0 prior to 6.6.7
Cisco FTD Software version from 6.7.0 prior to 7.0.4
Cisco FTD Software version from 7.1.0 prior to 7.1.0.3
Cisco FTD Software version from 7.2.0 prior to 7.2.1
QID Detection Logic (Authenticated):
This QID will check the version retrieved via Unix Auth using "show version" command.
Successful exploitation of this vulnerability could allow the attacker to cause resource exhaustion, resulting in a DoS condition.
Customers are advised to refer to cisco-sa-asa-webvpn-dos-3GhZQBAS for more information.
- cisco-sa-asa-webvpn-dos-3GhZQBAS -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-webvpn-dos-3GhZQBAS
CVEs related to QID 317379
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-asa-webvpn-dos-3GhZQBAS |
|