- Firepower 4120 Security Appliance
- Firepower 4140 Security Appliance
- Firepower 4150 Security Appliance
- FTD Virtual
Published on: 30 January 2018
Last update on: 06 February 2018
Cisco has released the security advisory to address a vulnerability in Cisco Adaptive Security Appliance (ASA) software with the webvpn feature enabled. An unauthenticated remote attacker could exploit the vulnerability by sending multiple specially crafted XML packets to the webvpn-configured interface on affected systems.
Cisco ASA Software running on the following Cisco products:
Successful exploitation of the vulnerability could lead to authentication bypass, arbitrary code execution, denial of services, system reload, or complete control of an affected system.
Software updates for affected systems are now available. Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk. For detailed information of the available patches, please refer to the section "Fixed Software" of corresponding security advisory at vendor's website.
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1
Users should contact their product support vendors for the fixes and assistance.
https://www.us-cert.gov/ncas/current-activity/2018/02/05/Cisco-Releases-Security-Updates
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1
https://www.us-cert.gov/ncas/current-activity/2018/01/29/Cisco-Releases-Security-Update
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0101