CVE-2018-0228 (CNNVD-201804-1110)
中文标题:
多款Cisco产品Adaptive Security Appliance和Firepower Threat Defense Software 输入验证错误漏洞
英文标题:
A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA...
漏洞描述
中文描述:
Cisco 3000 Series Industrial Security Appliances(ISR)等都是美国思科(Cisco)公司的安全防火墙设备。Adaptive Security Appliance(ASA)和Firepower Threat Defense(FTD)Software都是使用在Cisco不同安全设备中的防火墙软件。 多款Cisco产品中ASA和FTD Software的ingress flow创建功能存在输入验证漏洞,该漏洞源于程序没有程序没有正确的处理内部软件的锁定,导致其他的系统进程可以使CPU进入循环。远程攻击者可通过发送恶意的IP数据包流利用该漏洞造成拒绝服务(CPU资源耗尽)。以下产品和版本受到影响:Cisco 3000 Series Industrial Security Appliances (ISA);ASA 5500 Series Adaptive Security Appliances;ASA 5500-X Series Next-Generation Firewalls;ASA Services Module for Cisco Catalyst 6500 Series Switches和Cisco 7600 Series Routers;Adaptive Security Virtual Appliances (ASAv);Firepower 2100 Series Security Appliances;Firepower 4110 Security Appliances;Firepower 9300 ASA Security Modules;Adaptive Security Appliance 9.1版本,9.2版本,9.3版本,9.4版本,9.5版本,9.6版本,9.7版本,9.8版本,9.9版本;Firepower Threat Defense (FTD) Software 6.0版本,6.0.1版本,6.1.0版本,6.2.0版本,6.2.1版本,6.2.2版本。
英文描述:
A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase upwards of 100% utilization, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to incorrect handling of an internal software lock that could prevent other system processes from getting CPU cycles, causing a high CPU condition. An attacker could exploit this vulnerability by sending a steady stream of malicious IP packets that can cause connections to be created on the targeted device. A successful exploit could allow the attacker to exhaust CPU resources, resulting in a DoS condition during which traffic through the device could be delayed. This vulnerability applies to either IPv4 or IPv6 ingress traffic. This vulnerability affects Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliances (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliances (ASAv), Firepower 2100 Series Security Appliances, Firepower 4110 Security Appliances, Firepower 9300 ASA Security Modules. Cisco Bug IDs: CSCvf63718.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | adaptive_security_appliance_software | * | - | - |
cpe:2.3:a:cisco:adaptive_security_appliance_software:*:*:*:*:*:*:*:*
|
| cisco | adaptive_security_appliance_software | 98.1\(12.187\) | - | - |
cpe:2.3:o:cisco:adaptive_security_appliance_software:98.1\(12.187\):*:*:*:*:*:*:*
|
| cisco | firepower_threat_defense | * | - | - |
cpe:2.3:a:cisco:firepower_threat_defense:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2018-0228 |
2025-11-11 15:19:35 | 2025-11-11 07:34:56 |
| NVD | nvd_CVE-2018-0228 |
2025-11-11 14:55:54 | 2025-11-11 07:43:33 |
| CNNVD | cnnvd_CNNVD-201804-1110 |
2025-11-11 15:10:00 | 2025-11-11 07:53:39 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 资源管理错误
- cnnvd_id: 未提取 -> CNNVD-201804-1110
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 8.6
- cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- cvss_version: NOT_EXTRACTED -> 3.1
- affected_products_count: 0 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']