// For flags

CVE-2019-1706

Cisco Adaptive Security Appliance Software IPsec Denial of Service Vulnerability

Severity Score

8.6
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A vulnerability in the software cryptography module of the Cisco Adaptive Security Virtual Appliance (ASAv) and Firepower 2100 Series running Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an unexpected reload of the device that results in a denial of service (DoS) condition. The vulnerability is due to a logic error with how the software cryptography module handles IPsec sessions. An attacker could exploit this vulnerability by creating and sending traffic in a high number of IPsec sessions through the targeted device. A successful exploit could cause the device to reload and result in a DoS condition.

Una vulnerabilidad en el módulo de programa de cryptography module of the Cisco Adaptive Security Virtual Appliance (ASAv) y Firepower versión 2100 Series que ejecuta Cisco Adaptive Security Appliance (ASA) el programa podría permitir que un atacante remoto no autenticado provoque una recarga inesperada del dispositivo que provoque una condición de denegación de servicio (DoS). La vulnerabilidad se debe a un error lógico en la forma en que el módulo de criptografía del programa maneja las sesiones IPsec. Un atacante podría explotar esta vulnerabilidad creando y enviando tráfico en un gran número de sesiones IPsec a través del dispositivo objetivo. Un exploit con éxito podría causar que el dispositivo se recargue y resulte en una condición de denegación de servicio (DoS).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2018-12-06 CVE Reserved
  • 2019-05-03 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-11-19 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-327: Use of a Broken or Risky Cryptographic Algorithm
  • CWE-404: Improper Resource Shutdown or Release
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Adaptive Security Appliance Software
Search vendor "Cisco" for product "Adaptive Security Appliance Software"
>= 9.9 <= 9.9.2.50
Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.9 <= 9.9.2.50"
-
Affected
in Cisco
Search vendor "Cisco"
Asa-5506-x
Search vendor "Cisco" for product "Asa-5506-x"
--
Safe
Cisco
Search vendor "Cisco"
Adaptive Security Appliance Software
Search vendor "Cisco" for product "Adaptive Security Appliance Software"
>= 9.9 <= 9.9.2.50
Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.9 <= 9.9.2.50"
-
Affected
in Cisco
Search vendor "Cisco"
Asa-5506h-x
Search vendor "Cisco" for product "Asa-5506h-x"
--
Safe
Cisco
Search vendor "Cisco"
Adaptive Security Appliance Software
Search vendor "Cisco" for product "Adaptive Security Appliance Software"
>= 9.9 <= 9.9.2.50
Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.9 <= 9.9.2.50"
-
Affected
in Cisco
Search vendor "Cisco"
Asa-5506w-x
Search vendor "Cisco" for product "Asa-5506w-x"
--
Safe
Cisco
Search vendor "Cisco"
Adaptive Security Appliance Software
Search vendor "Cisco" for product "Adaptive Security Appliance Software"
>= 9.9 <= 9.9.2.50
Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.9 <= 9.9.2.50"
-
Affected
in Cisco
Search vendor "Cisco"
Asa-5508-x
Search vendor "Cisco" for product "Asa-5508-x"
--
Safe
Cisco
Search vendor "Cisco"
Adaptive Security Appliance Software
Search vendor "Cisco" for product "Adaptive Security Appliance Software"
>= 9.9 <= 9.9.2.50
Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.9 <= 9.9.2.50"
-
Affected
in Cisco
Search vendor "Cisco"
Asa-5516-x
Search vendor "Cisco" for product "Asa-5516-x"
--
Safe
Cisco
Search vendor "Cisco"
Adaptive Security Appliance Software
Search vendor "Cisco" for product "Adaptive Security Appliance Software"
>= 9.9 <= 9.9.2.50
Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.9 <= 9.9.2.50"
-
Affected
in Cisco
Search vendor "Cisco"
Asa-5525-x
Search vendor "Cisco" for product "Asa-5525-x"
--
Safe
Cisco
Search vendor "Cisco"
Adaptive Security Appliance Software
Search vendor "Cisco" for product "Adaptive Security Appliance Software"
>= 9.9 <= 9.9.2.50
Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.9 <= 9.9.2.50"
-
Affected
in Cisco
Search vendor "Cisco"
Asa-5545-x
Search vendor "Cisco" for product "Asa-5545-x"
--
Safe
Cisco
Search vendor "Cisco"
Adaptive Security Appliance Software
Search vendor "Cisco" for product "Adaptive Security Appliance Software"
>= 9.9 <= 9.9.2.50
Search vendor "Cisco" for product "Adaptive Security Appliance Software" and version " >= 9.9 <= 9.9.2.50"
-
Affected
in Cisco
Search vendor "Cisco"
Asa-5555-x
Search vendor "Cisco" for product "Asa-5555-x"
--
Safe