CVE-2018-15388 describes a denial-of-service vulnerability affecting Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software. An unauthenticated, remote attacker can exploit this by sending numerous WebVPN login requests, leading to excessive CPU utilization and a DoS condition. Rated 8.6 HIGH on CVSS, this vulnerability is easily exploitable over the network with no user interaction required, resulting in high availability impact. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for disruption warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.4.4.34CPE matchmatch criteria | cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.5, < 9.6.4.25CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.7, < 9.8.4CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.9, < 9.9.2.50CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
< 6.2.3.12CPE matchmatch criteria | cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.