CVE-2018-0227 describes a vulnerability in Cisco ASA and FTD Software's SSL VPN Client Certificate Authentication feature. This flaw allows an unauthenticated, remote attacker to bypass certificate verification and establish an SSL VPN connection without a valid private key and certificate pair. With a CVSS score of 7.5 (High), the vulnerability has a low attack complexity and high impact on integrity, as it enables unauthorized access to the VPN. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for unauthorized network access warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.4.4, <= 9.4.4.13CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.5.3.7, <= 9.5.3.9CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.6.2.9, <= 9.6.2.21CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.6.3, <= 9.6.3.17CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
9.4.3.1CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.