
====================================================================


                             CERT-Renater

                 Note d'Information No. 2018/VULN159
_____________________________________________________________________

DATE                : 19/04/2018

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Cisco ASA Software, Cisco FTD Software.

=====================================================================
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa_inspect
_____________________________________________________________________

Cisco Security Advisory: Cisco Adaptive Security Appliance Application
Layer Protocol Inspection Denial of Service Vulnerabilities

Advisory ID: cisco-sa-20180418-asa_inspect

Revision: 1.0

For Public Release: 2018 April 18 16:00 GMT

Last Updated: 2018 April 18 16:00 GMT

CVE ID(s): CVE-2018-0240

CVSS Score v(3): 8.6 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

+---------------------------------------------------------------------

Summary

=======

Multiple vulnerabilities in the Application Layer Protocol Inspection
feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco
Firepower Threat Defense (FTD) Software could allow an unauthenticated,
remote attacker to trigger a reload of an affected device, resulting in
a denial of service (DoS) condition.

The vulnerabilities are due to logical errors during traffic inspection.
An attacker could exploit these vulnerabilities by sending a high volume
of malicious traffic across an affected device. An exploit could allow
the attacker to cause a deadlock condition, resulting in a reload of an
affected device.

Cisco has released software updates that address these vulnerabilities.
There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa_inspect
["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa_inspect"]

==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================





