CVE-2018-15383
Cisco Firepower Threat Defense
A vulnerability in the cryptographic hardware accelerator driver of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a temporary denial of service (DoS) condition. The vulnerability exists because the affected devices have a limited amount of Direct Memory Access (DMA) memory and the affected software improperly handles resources in low-memory conditions. An attacker could exploit this vulnerability by sending a sustained, high rate of malicious traffic to an affected device to exhaust memory on the device. A successful exploit could allow the attacker to exhaust DMA memory on the affected device, which could cause the device to reload and result in a temporary DoS condition.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.5 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Weakness
- CWE-400
- Assigned by
- psirt@cisco.com
Dates
- Published
- 2018-10-05
- Last modified
- 2026-08-11
- Sources
- NVD
Affected products
- Cisco Firepower Threat Defense6.0
- Cisco Secure Firewall Threat Defense6.0.1, 6.1.0, 6.2.0, 6.2.2, 6.2.3
- Cisco Adaptive Security Appliance Software9.3, 9.4, 9.5, 9.6, 9.6\(43\), 9.7, 9.8, 9.9, 9.9\(28\)
As listed in the NVD configuration data. Not a statement about your estate.