HTTP: Cisco ASA Clientless SSL VPN Common Internet Filesystem Heap Overflow

This signature detects attempts to exploit a known vulnerability against Cisco ASA Clientless. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the Cisco ASA Clientless.

Extended Description

A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remote attacker to cause a heap overflow. The vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by sending a crafted URL to the affected system. An exploit could allow the remote attacker to cause a reload of the affected system or potentially execute code. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability affects systems configured in routed firewall mode only and in single or multiple context mode. This vulnerability can be triggered by IPv4 or IPv6 traffic. A valid TCP connection is needed to perform the attack. The attacker needs to have valid credentials to log in to the Clientless SSL VPN portal. Vulnerable Cisco ASA Software running on the following products may be affected by this vulnerability: Cisco ASA 5500 Series Adaptive Security Appliances, Cisco ASA 5500-X Series Next-Generation Firewalls, Cisco Adaptive Security Virtual Appliance (ASAv), Cisco ASA for Firepower 9300 Series, Cisco ASA for Firepower 4100 Series. Cisco Bug IDs: CSCvc23838.

Affected Products

Cisco adaptive_security_appliance_software

References

BugTraq: 96161

CVE: CVE-2017-3807

Short Name
HTTP:CISCO:ASA-CIFS-OF
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
ASA CVE-2017-3807 Cisco Clientless Common Filesystem Heap Internet Overflow SSL VPN bid:96161
Release Date
06/11/2020
Supported Platforms

srx-branch-12.3

srx-branch-19.3

vsrx3bsd-19.2

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

srx-19.4

srx-12.3

vsrx-19.2

srx-19.3

Sigpack Version
3735
False Positive
Unknown
Vendors

Cisco

CVSS Score

8.0

Found a potential security threat?