Cisco Adaptive Security Appliance (ASA) Software 및 Cisco Firepower Threat Defense (FTD) Software의 관리 및 VPN web servers에 존재하는 취약점으로 인해 인증되지 않은 원격 공격자가 장치를 예기치 않게 다시 로드하게 하여 서비스 거부(DoS) 상태를 일으킬 수 있습니다. 이 취약점은 HTTP header를 구문 분석할 때 오류 검사가 불완전하여 발생합니다. 공격자는 장치에서 표적으로 삼은 web server에 조작된 HTTP 요청을 전송하여 이 취약점을 악용할 수 있습니다. 악용에 성공하면 장치가 다시 로드될 때 공격자가 DoS 상태를 일으킬 수 있습니다.
Cisco Adaptive Security Appliance (ASA) Software 및 Cisco Firepower Threat Defense (FTD) Software의 관리 및 VPN web servers에 존재하는 취약점으로 인해 인증되지 않은 원격 공격자가 장치를 예기치 않게 다시 로드하게 하여 서비스 거부(DoS) 상태를 일으킬 수 있습니다. 이 취약점은 HTTP header를 구문 분석할 때 오류 검사가 불완전하여 발생합니다. 공격자는 장치에서 표적으로 삼은 web server에 조작된 HTTP 요청을 전송하여 이 취약점을 악용할 수 있습니다. 악용에 성공하면 장치가 다시 로드될 때 공격자가 DoS 상태를 일으킬 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to incomplete error checking when parsing an HTTP header. An attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted web server on a device. A successful exploit could allow the attacker to cause a DoS condition when the device reloads.