CVE-2018-0296
Last modified
CVE-2018-0296 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.90% chance of exploitation in the next 30 days.
Description
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Adaptive Security Appliance Software | >= 9.1, < 9.1.7.29 |
| Cisco | Adaptive Security Appliance Software | >= 9.2, < 9.2.4.33 |
| Cisco | Adaptive Security Appliance Software | >= 9.3, < 9.4.4.18 |
| Cisco | Adaptive Security Appliance Software | >= 9.5, < 9.6.4.8 |
| Cisco | Adaptive Security Appliance Software | >= 9.7, < 9.7.1.24 |
| Cisco | Adaptive Security Appliance Software | >= 9.8, < 9.8.2.28 |
| Cisco | Adaptive Security Appliance Software | >= 9.9, < 9.9.2.1 |
| Cisco | Firepower Threat Defense | 6.2.3-85.02 |
| Cisco | Firepower Threat Defense | 6.2.3-851 |
| Cisco | Secure Firewall Threat Defense | >= 6.0, < 6.1.0 |
| Cisco | Secure Firewall Threat Defense | >= 6.2.1, < 6.2.2.3 |
| Cisco | Secure Firewall Threat Defense | 6.2.3 |
| Cisco | Secure Firewall Threat Defense | 6.2.3.1 |
References
- http://packetstormsecurity.com/files/154017/Cisco-Adaptive-Security-Appliance-Path-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/104612Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041076Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01Third Party Advisory, US Government Resource
- https://www.exploit-db.com/exploits/44956/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/154017/Cisco-Adaptive-Security-Appliance-Path-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/104612Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041076Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01Third Party Advisory, US Government Resource
- https://www.exploit-db.com/exploits/44956/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0296US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2018-0296?
How severe is CVE-2018-0296?
How do I fix CVE-2018-0296?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-0290A vulnerability in the TCP stack of Cisco SocialMiner could …
- CVE-2018-0291A vulnerability in the Simple Network Management Protocol (S…
- CVE-2018-0292A vulnerability in the Internet Group Management Protocol (I…
- CVE-2018-0293A vulnerability in role-based access control (RBAC) for Cisc…
- CVE-2018-0294A vulnerability in the write-erase feature of Cisco FXOS Sof…
- CVE-2018-0295A vulnerability in the Border Gateway Protocol (BGP) impleme…
- CVE-2018-0297A vulnerability in the detection engine of Cisco Firepower T…5.8
- CVE-2018-0298A vulnerability in the web UI of Cisco FXOS and Cisco UCS Fa…
- CVE-2018-0299A vulnerability in the Simple Network Management Protocol (S…
- CVE-2018-0300A vulnerability in the process of uploading new application …
- CVE-2018-0301A vulnerability in the NX-API feature of Cisco NX-OS Softwar…
- CVE-2018-0302A vulnerability in the CLI parser of Cisco FXOS Software and…7.8
Are you affected by CVE-2018-0296?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
