QID 317380
Date Published: 2023-11-09
QID 317380: Cisco Adaptive Security Appliance (ASA) Software Remote Access Virtual Private Network (VPN) Denial of Service (DoS) Vulnerability (cisco-sa-asa-webvpn-dos-3GhZQBAS)
This vulnerability is due to improper handling of HTTPS requests. An attacker could exploit this vulnerability by sending crafted HTTPS requests to an affected system.
Affected Products
Cisco Adaptive Security Appliance (ASA) version from 9.8.1 prior to 9.18.1.3
9.8.1 prior to 9.8.4.46
9.12.1 prior to 9.12.4.47
9.14.1 prior to 9.14.4.12
9.15.1 prior to 9.16.3.15
9.17.1 prior to 9.17.1.10
9.18.1 prior to 9.18.1.3
QID Detection Logic (Authenticated):
The check matches Cisco ASA OS version retrieved via Unix Auth using version command. and executes the following commands provided in the Cisco Security advisory:
show running-config crypto ikev2 | include crypto ikev2 enable
show running-config webvpn | include ^ enable
Successful exploitation of this vulnerability could allow the attacker to cause resource exhaustion, resulting in a DoS condition.
Customers are advised to refer to cisco-sa-asa-webvpn-dos-3GhZQBAS for more information.
- cisco-sa-asa-webvpn-dos-3GhZQBAS -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-webvpn-dos-3GhZQBAS
CVEs related to QID 317380
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-asa-webvpn-dos-3GhZQBAS |
|