Loading...
Loading...
A vulnerability in the RADIUS client implementation of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Thread Defense (FTD) software could allow an authenticated, remote attacker to trigger a reload of the system, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient correlation between active VPN sessions and the AAA server responsible for handling each session. An attacker could exploit this vulnerability by sending a crafted Change of Authorization (CoA) message to the ASA. An exploit could allow the attacker to trigger a crash of the coa_task process.
1. At least two aaa-server groups configured on ASA, at least one with the Change of Authorization (CoA, dynamic-authorization) feature enabled and at least one with the CoA feature disabled. 2. At least one tunnel-group references a aaa-server group with CoA disabled.
There are no workarounds that address this vulnerability.
The Cisco PSIRT has assigned this bug the following CVSS version 3 score. The Base CVSS score as of the time of evaluation is 6.3: https://tools.cisco.com/security/center/cvssCalculator.x?version=3.0&vector=CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X Despite the CVSS version 3 score of 6.3 Cisco PSIRT has assigned this vulnerability a low quantitative metric, as exploiting this vulnerability is extremely difficult. No CVE ID has been assigned to this issue. Additional information on Cisco's security vulnerability policy can be found at the following URL: http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html
Click on a version to see all relevant bugs
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.