PT-2018-1974 · Cisco · Cisco Asa+1
Published
2018-10-31
·
Updated
2023-08-15
·
CVE-2018-15454
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Adaptive Security Appliance (ASA) Software (affected versions not specified)
Cisco Firepower Threat Defense (FTD) Software (affected versions not specified)
Description
A vulnerability in the Session Initiation Protocol (SIP) inspection engine could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of SIP traffic. An attacker could exploit this vulnerability by sending SIP requests designed to specifically trigger this issue at a high rate across an affected device.
Recommendations
For Cisco Adaptive Security Appliance (ASA) Software, update to a version that addresses this vulnerability.
For Cisco Firepower Threat Defense (FTD) Software, update to a version that addresses this vulnerability.
As a temporary workaround, consider restricting SIP traffic to minimize the risk of exploitation.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Asa
Cisco Ftd