ReviewHigh

CVE-2019-1697

Cisco Cisco Adaptive Security Appliance (ASA) Software, adaptive security appliance software, asa 5505

A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of LDAP packets sent to an affected device. An attacker could exploit these vulnerabilities by sending a crafted LDAP packet, using Basic Encoding Rules (BER), to be processed by an affected device. A successful ex...

CVSS
7.5
EPSS
2.03%
79.7% percentile
CISA KEV
Not listed
Published
2019.05.04
PRIORITY ASSESSMENT

Review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability2.03%
Technical severityCVSS 7.5

Vulnerability overview

A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of LDAP packets sent to an affected device. An attacker could exploit these vulnerabilities by sending a crafted LDAP packet, using Basic Encoding Rules (BER), to be processed by an affected device. A successful ex...

Affected product and versions

Product
Cisco Cisco Adaptive Security Appliance (ASA) Software, adaptive security appliance software, asa 5505
Affected versions
>= unspecified < 9.6(4.21), < 9.6.4.25, >= 9.7 < 9.8.4, >= 9.9 < 9.9.2.50, >= 9.10 < 9.10.1.17, < 6.2.3.12, >= 6.3.0 < 6.3.0.3
Fixed versions
9.6.4.25, 9.8.4, 9.9.2.50, 9.10.1.17, 6.2.3.12, 6.3.0.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Cisco Cisco Adaptive Security Appliance (ASA) Software, adaptive security appliance software, asa 5505 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-20