EXPOSURES › CVE-2018-0296
CVE-2018-0296
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco ASA suffered a DoS vulnerability from improper HTTP URL input validation that was actively exploited in the wild.
The Cisco Adaptive Security Appliance (ASA) contained an improper input validation flaw with HTTP URLs, allowing attackers to trigger denial-of-service or information disclosure. This failure matters to DIB organizations because edge security devices like the ASA are critical infrastructure; if compromised or taken offline, it disrupts network security and violates CMMC/NIST 800-171 controls requiring continuous monitoring and patching. Organizations must ensure all ASA devices are patched and monitored for exploitation attempts.
Shame score — The vulnerability was actively exploited in the wild (KEV) and linked to CISA emergency directives, indicating negligent patching and avoidable exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |