CVE-2018-15454 is a denial-of-service vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software. An unauthenticated, remote attacker can exploit this by sending a high rate of specially crafted SIP requests, causing the affected device to reload or experience high CPU usage. With a CVSS score of 8.6 (High), this vulnerability is easily exploitable over the network with low attack complexity, leading to a complete loss of availability. While there is no public exploit code or KEV entry, media coverage and community discussion indicate awareness, and it was reported as a zero-day at the time of discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.4, < 9.4.4.27CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.6, < 9.6.4.18CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.8, < 9.8.3.16CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.9, < 9.9.2.32CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* | ||
>= 9.10, < 9.10.1.2CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.