Executive brief
A vulnerability in the web interface of Cisco ASA and FTD software due to improper input validation of HTTP URLs allows unauthenticated remote attackers to cause a denial-of-service (DoS) by triggering an unexpected reload. On certain software releases, the vulnerability may instead allow unauthorized information disclosure via directory traversal techniques.
Affected products
- Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1.7.29, 9.2 before 9.2.4.33, 9.3 before 9.4.4.18, 9.5 before 9.6.4.8, 9.7 before 9.7.1.24, 9.8 before 9.8.2.28, 9.9 before 9.9.2.1
- Cisco Firepower Threat Defense (FTD) Software
Timeline
- 2018-06-06: disclosed: Vendor advisory published by Cisco
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Confirmed as exploited in the wild per CISA KEV and advisory metadata