CVE-2018-0231: Input Validation
A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a malicious TLS message to an interface enabled for Secure Layer Socket (SSL) services on an affected device. Messages using SSL Version 3 (SSLv3) or SSL Version 2 (SSLv2) cannot be be used to exploit this vulnerability. An exploit could allow the attacker to cause a buffer underflow, triggering a crash on an affected device. This vulnerability affects Cisco ASA Software and Cisco FTD Software that is running on the following Cisco products: Adaptive Security Virtual Appliance (ASAv), Firepower Threat Defense Virtual (FTDv), Firepower 2100 Series Security Appliance. Cisco Bug IDs: CSCve18902, CSCve34335, CSCve38446.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0231?
CVE-2018-0231 has been rated as a high severity vulnerability due to its potential to enable a denial of service attack.
How do I fix CVE-2018-0231?
To mitigate CVE-2018-0231, upgrade Cisco Adaptive Security Appliance Software or Cisco Firepower Threat Defense Software to the latest versions provided by Cisco.
What types of devices are affected by CVE-2018-0231?
CVE-2018-0231 affects Cisco Adaptive Security Appliances and Cisco Firepower Threat Defense devices running specific vulnerable software versions.
Can CVE-2018-0231 be exploited remotely?
Yes, CVE-2018-0231 can be exploited by an unauthenticated remote attacker.
What is the impact of CVE-2018-0231 on affected systems?
The impact of CVE-2018-0231 is a denial of service condition, causing the affected device to reload.