CVE-2018-0101 is a critical vulnerability in the SSL VPN functionality of Cisco Adaptive Security Appliance (ASA) Software, affecting numerous Cisco products including ASA 5500 Series and Firepower appliances. This flaw, a double-free memory error (CWE-415), allows an unauthenticated, remote attacker to cause a system reload or execute arbitrary code by sending crafted XML packets. With a CVSS score of 10.0, it presents a severe risk due to its network-based attack vector, low complexity, and potential for complete system compromise. Exploit code is publicly available (EDB-43986), and the vulnerability has seen significant community discussion and media coverage, with reports of active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.1.7.23CPE matchmatch criteria | cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.2.0, < 9.2.4.27CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.3.0, < 9.4.4.16CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.5.0, < 9.6.4.3CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.7.0, < 9.7.1.21CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.