Cisco Adaptive Security Appliance Software denial of service | CVE-2022-20745
NAME
Cisco Adaptive Security Appliance Software denial of service
- Platforms Affected:
Cisco Adaptive Security Appliance Software 8.2(1)
Cisco Adaptive Security Appliance Software 8.2(2)
Cisco Adaptive Security Appliance Software 8.2(3)
Cisco Adaptive Security Appliance Software 8.3(1)
Cisco Adaptive Security Appliance Software 8.2(3.9)
Cisco Adaptive Security Appliance Software 8.2(4)
Cisco Adaptive Security Appliance Software 7.0
Cisco Adaptive Security Appliance Software 7.0(0)
Cisco Adaptive Security Appliance Software 7.0(2)
Cisco Adaptive Security Appliance Software 7.0(4)
Cisco Adaptive Security Appliance Software 7.0(5)
Cisco Adaptive Security Appliance Software 7.0(5.2)
Cisco Adaptive Security Appliance Software 7.0(6.7)
Cisco Adaptive Security Appliance Software 7.0.1
Cisco Adaptive Security Appliance Software 7.0.1.4
Cisco Adaptive Security Appliance Software 7.0.2
Cisco Adaptive Security Appliance Software 7.0.4
Cisco Adaptive Security Appliance Software 7.0.4.3
Cisco Adaptive Security Appliance Software 7.0.5
Cisco Adaptive Security Appliance Software 7.0.6
Cisco Adaptive Security Appliance Software 7.0.7
Cisco Adaptive Security Appliance Software 7.0.8
Cisco Adaptive Security Appliance Software 7.0.8 Interim
Cisco Adaptive Security Appliance Software 7.1
Cisco Adaptive Security Appliance Software 7.1(2)
Cisco Adaptive Security Appliance Software 7.1(2.27)
Cisco Adaptive Security Appliance Software 7.1(2.48)
Cisco Adaptive Security Appliance Software 7.1(2.49)
Cisco Adaptive Security Appliance Software 7.1(2.5)
Cisco Adaptive Security Appliance Software 7.1(5)
Cisco Adaptive Security Appliance Software 7.1.1
Cisco Adaptive Security Appliance Software 7.1.2
Cisco Adaptive Security Appliance Software 7.2
Cisco Adaptive Security Appliance Software 7.2(1)
Cisco Adaptive Security Appliance Software 7.2(1.22)
Cisco Adaptive Security Appliance Software 7.2(2)
Cisco Adaptive Security Appliance Software 7.2(2.10)
Cisco Adaptive Security Appliance Software 7.2(2.14)
Cisco Adaptive Security Appliance Software 7.2(2.15)
Cisco Adaptive Security Appliance Software 7.2(2.16)
Cisco Adaptive Security Appliance Software 7.2(2.17)
Cisco Adaptive Security Appliance Software 7.2(2.18)
Cisco Adaptive Security Appliance Software 7.2(2.19)
Cisco Adaptive Security Appliance Software 7.2(2.48)
Cisco Adaptive Security Appliance Software 7.2(2.5)
Cisco Adaptive Security Appliance Software 7.2(2.7)
Cisco Adaptive Security Appliance Software 7.2(2.8)
Cisco Adaptive Security Appliance Software 7.2.1
Cisco Adaptive Security Appliance Software 7.2.2
Cisco Adaptive Security Appliance Software 7.2.3
Cisco Adaptive Security Appliance Software 7.2.4
Cisco Adaptive Security Appliance Software 7.2.5
Cisco Adaptive Security Appliance Software 8.0
Cisco Adaptive Security Appliance Software 8.0.2
Cisco Adaptive Security Appliance Software 8.0.3
Cisco Adaptive Security Appliance Software 8.0.4
Cisco Adaptive Security Appliance Software 8.0.5
Cisco Adaptive Security Appliance Software 8.2.1
Cisco Adaptive Security Appliance Software 8.2.2
Cisco Adaptive Security Appliance Software 8.2.2 Interim
Cisco Adaptive Security Appliance Software 8.2.3
Cisco Adaptive Security Appliance Software 8.3.1
Cisco Adaptive Security Appliance Software 8.3.1 Interim
Cisco Adaptive Security Appliance Software 8.3.2
Cisco Adaptive Security Appliance Software 7.0(1)
Cisco Adaptive Security Appliance Software 7.0(6)
Cisco Adaptive Security Appliance Software 7.0(7)
Cisco Adaptive Security Appliance Software 7.0(8)
Cisco Adaptive Security Appliance Software 7.2(3)
Cisco Adaptive Security Appliance Software 7.2(4)
Cisco Adaptive Security Appliance Software 7.2(5)
Cisco Adaptive Security Appliance Software 8.0(2)
Cisco Adaptive Security Appliance Software 8.0(3)
Cisco Adaptive Security Appliance Software 8.0(4)
Cisco Adaptive Security Appliance Software 8.1
Cisco Adaptive Security Appliance Software 8.2(4.1)
Cisco Adaptive Security Appliance Software 8.2(4.4)
Cisco Adaptive Security Appliance Software 8.4(1)
Cisco Adaptive Security Appliance Software 8.4(2)
Cisco Adaptive Security Appliance Software 8.4(1.11)
Cisco Adaptive Security Appliance Software 8.5(1)
Cisco Adaptive Security Appliance Software 8.5
Cisco Adaptive Security Appliance Software 8.3(2)
Cisco Adaptive Security Appliance Software 8.2(5)
Cisco Adaptive Security Appliance Software 8.0(5)
Cisco Adaptive Security Appliance Software 8.4
Cisco Adaptive Security Appliance Software 8.4(2.11)
Cisco Adaptive Security Appliance Software 8.5(1.4)
Cisco Adaptive Security Appliance Software 8.2
Cisco Adaptive Security Appliance Software 8.7.1
Cisco Adaptive Security Appliance Software 8.7.1.1
Cisco Adaptive Security Appliance Software
Cisco Adaptive Security Appliance Software 8.4(5)
Cisco Adaptive Security Appliance Software 9.1(1)
Cisco Adaptive Security Appliance Software 8.4(0.3)
Cisco Adaptive Security Appliance Software 9.0
Cisco Adaptive Security Appliance Software 9.0(1)
Cisco Adaptive Security Appliance Software 9.0(2)
Cisco Adaptive Security Appliance Software 9.0(3)
Cisco Adaptive Security Appliance Software 8.7
Cisco Adaptive Security Appliance Software 8.7(1.1)
Cisco Adaptive Security Appliance Software 8.7(1.3)
Cisco Adaptive Security Appliance Software 9.1
Cisco Adaptive Security Appliance Software 9.1(1.7)
Cisco Adaptive Security Appliance Software 9.1(2)
Cisco Adaptive Security Appliance Software 8.4(3)
Cisco Adaptive Security Appliance Software 8.4(4.11)
Cisco Adaptive Security Appliance Software 8.4(6)
Cisco Adaptive Security Appliance Software 8.6(1.3)
Cisco Adaptive Security Appliance Software 8.6(1.10)
Cisco Adaptive Security Appliance Software 8.6(1)
Cisco Adaptive Security Appliance Software 8.6
Cisco Adaptive Security Appliance Software 8.5(1.17)
Cisco Adaptive Security Appliance Software 8.3(2.37)
Cisco Adaptive Security Appliance Software 8.3(2.34)
Cisco Adaptive Security Appliance Software 8.2(5.38)
Cisco Adaptive Security Appliance Software 8.2(5.35)
Cisco Adaptive Security Appliance Software 8.0(5.31)
Cisco Adaptive Security Appliance Software 8.0(5.28)
Cisco Adaptive Security Appliance Software 9.1(3)
Cisco Adaptive Security Appliance Software 9.4.3.1
Cisco Adaptive Security Appliance Software 9.4.3.2
Cisco Adaptive Security Appliance Software 9.4.4
Cisco Adaptive Security Appliance Software 9.4.4.13
Cisco Adaptive Security Appliance Software 9.5.2.7
Cisco Adaptive Security Appliance Software 9.5.2.8
Cisco Adaptive Security Appliance Software 9.5.3.7
Cisco Adaptive Security Appliance Software 9.5.3.9
Cisco Adaptive Security Appliance Software 9.6.2.9
Cisco Adaptive Security Appliance Software 9.6.2.21
Cisco Adaptive Security Appliance Software 9.6.3
Cisco Adaptive Security Appliance Software 9.6.3.17
Cisco Firepower Threat Defense (FTD) Software 6.2.0
Cisco Firepower Threat Defense (FTD) Software 6.2.1
Cisco Firepower Threat Defense (FTD) Software 6.2.2
Cisco Firepower Threat Defense (FTD) Software 6.2.3
Cisco Firepower Threat Defense (FTD) Software 6.5.0
Cisco Firepower Threat Defense (FTD) Software 6.3.0
Cisco Firepower Threat Defense (FTD) Software 6.4.0
Cisco Firepower Threat Defense (FTD) Software 7.0.1 - Risk Level:
8.6 - Exploitability:
Unproven - Consequences:
Denial of Service
DESCRIPTION
Cisco Adaptive Security Appliance Software and Cisco Firepower Threat Defense Software are vulnerable to a denial of service, caused by improper input validation in the web services interface when parsing HTTPS requests. By sending a specially-crafted HTTPS request, a remote attacker could exploit this vulnerability to cause the device to reload.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Refer to Cisco Security Advisory cisco-sa-asafdt-webvpn-dos-tzPSYern for patch, upgrade or suggested workaround information. See References.
- Reference Link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asafdt-webvpn-dos-tzPSYern - Reference Link:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20745
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.