CVE-2018-0101
Cisco Adaptive Security Appliance, adaptive security appliance software, secure firewall threat defense
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled on the Cisco ASA device. An attacker could exploit this vulnerability by sending multiple, crafted XML packets to a webvpn-configured interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full c...
- CVSS
- 10
- EPSS
- 86.8% 99.7% percentile
- CISA KEV
- Not listed
- Published
- 2018.01.30