Advertisement
Top

Hackers actively exploiting vulnerabilities in Cisco security appliances

November 5, 2018

Category:

Networking giant Cisco is warning customers that attackers are actively exploiting a vulnerability in the company’s Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software.

CVE-2018-15454 describes a vulnerability in the Session Initiation Protocol (SIP) inspection engine of ASA and FTD software. Exploited correctly, the flaw allows a remote attacker to deploy a denial of service (DoS) condition by reloading or triggering high CPU cycles.

Caused by improper handling of SIP traffic, the flaw could allow bad actors to send SIP requests designed to specifically trigger the issue at a high rate across an affected device.

Read More on Hot for Security