#VU15358 Improper input validation in Cisco Adaptive Security Appliance (ASA) - CVE-2018-15397

 

#VU15358 Improper input validation in Cisco Adaptive Security Appliance (ASA) - CVE-2018-15397

Published: October 14, 2018


Vulnerability identifier: #VU15358
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-15397
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco Adaptive Security Appliance (ASA)
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists in the implementation of Traffic Flow Confidentiality (TFC) over IPsec functionality due to an error during renegotiating of the encryption key for an IPsec tunnel when certain TFC traffic is in flight. A remote attacker can send a malicious stream of TFC traffic through an established IPsec tunnel and cause a daemon process on the affected device to crash.

Remediation

Install update from vendor's website.

External links