Critical Patch Update for Cisco Adaptive Security Appliance (ASA)
Cisco has issued a warning to customers using Adaptive Security Appliance (ASA) software to patch a critical VPN vulnerability.

 

Summary from Cisco

A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code.

 

The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled on the Cisco ASA device. An attacker could exploit this vulnerability by sending multiple, crafted XML packets to a webvpn-configured interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system, or cause a reload of the affected device.

 

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1

 

Cerium Networks provides quality information to its customers. We rely on some outside sources and do not guarantee the accuracy or completeness of the information contained in links associated with this message.

Related Articles

A sampling of other articles you may enjoy if you liked this one.

Cerium Networks can help your business meet or exceed your planning engagements.
Planning for New Technologies? 3 Critical Aspects to Consider
Nov 28, 2018

Today's digital infrastructure technologies can offer unprecedented levels of strategic value to you...

Read More
Cerium offers NASPO ValuePoint Storage products and services from Dell EMC
Sep 10, 2018

Take the headaches out of procurement Cerium Networks provides competitive pricing, streamlined pro...

Read More
Smart Moves for Business—End-User Phone Training
Sep 4, 2018

The telephone is often the first human contact someone has with your business. They’ve checked out...

Read More
Stay in the Know

Stay in the Know

Don't miss out on critical security advisories, industry news, and technology insights from our experts. Sign up today!

You have Successfully Subscribed!