Critical Patch Update for Cisco Adaptive Security Appliance (ASA)
Cisco has issued a warning to customers using Adaptive Security Appliance (ASA) software to patch a critical VPN vulnerability.

 

Summary from Cisco

A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code.

 

The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled on the Cisco ASA device. An attacker could exploit this vulnerability by sending multiple, crafted XML packets to a webvpn-configured interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system, or cause a reload of the affected device.

 

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1

 

Cerium Networks provides quality information to its customers. We rely on some outside sources and do not guarantee the accuracy or completeness of the information contained in links associated with this message.

Related Articles

A sampling of other articles you may enjoy if you liked this one.

Gregg Pruett Joins Cisco’s Partner Technical Advisory Board
Jun 26, 2019

Cisco’s Global Partner Technology Advisory Board (PTAB) met recently in San Diego, bringing togeth...

Read More
Meet Mike Portera MPM, PMP, PMO Director
Jun 10, 2019

Mike Portera joined Cerium in October of 2018 as Director, PMO, bringing over 25 years of multi-indu...

Read More
Dell Technologies World 2019 Conference Recap
Jun 3, 2019

Dell Technologies World 2019 Conference Recap More than 15,000 industry leaders and professionals f...

Read More
Stay in the Know

Stay in the Know

Don't miss out on critical security advisories, industry news, and technology insights from our experts. Sign up today!

You have Successfully Subscribed!