Skip to content
COOEY

EXPOSURES › CVE-2018-0296

CVE-2018-0296

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-0296 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Cisco ASA suffered a DoS vulnerability from improper HTTP URL input validation that was actively exploited in the wild.

The Cisco Adaptive Security Appliance (ASA) contained an improper input validation flaw with HTTP URLs, allowing attackers to trigger denial-of-service or information disclosure. This failure matters to DIB organizations because edge security devices like the ASA are critical infrastructure; if compromised or taken offline, it disrupts network security and violates CMMC/NIST 800-171 controls requiring continuous monitoring and patching. Organizations must ensure all ASA devices are patched and monitored for exploitation attempts.

Shame score — The vulnerability was actively exploited in the wild (KEV) and linked to CISA emergency directives, indicating negligent patching and avoidable exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized