← Vulnerability feed

Vulnerability record · CVE-2018-0101 · published 29 January 2018

CVE-2018-0101: Cisco ASA WebVPN double free allows unauthenticated remote code execution

Cisco · Adaptive Security Appliance Software

Cisco ASA Software contains a double free in the SSL VPN (webvpn) feature, triggered when crafted XML packets are sent to a webvpn-enabled interface. Because the flaw is reachable without authentication and can lead to code execution or a device reload, it is a severe risk to any internet-facing ASA or FTD device with webvpn enabled.

10.0 CVSS 3.0 Critical EPSS 87% · top 0.3% CWE-415 · Double free
10.0CVSS 3.0 base score, v2 10.0
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References, 4 tagged exploit
11 Aug 2026Last modified by NVD

Description

A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled on the Cisco ASA device. An attacker could exploit this vulnerability by sending multiple, crafted XML packets to a webvpn-configured interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system, or cause a reload of the affected device. This vulnerability affects Cisco ASA Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, ASA 1000V Cloud Firewall, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4110 Security Appliance, Firepower 9300 ASA Security Module, Firepower Threat Defense Software (FTD). Cisco Bug IDs: CSCvg35618.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 10.0 with no authentication or user interaction, public exploit code and a very high EPSS score make this an urgent patch for any exposed webvpn-enabled ASA or FTD.

What it is

Cisco ASA Software contains a double free in the SSL VPN (webvpn) feature, triggered when crafted XML packets are sent to a webvpn-enabled interface. Because the flaw is reachable without authentication and can lead to code execution or a device reload, it is a severe risk to any internet-facing ASA or FTD device with webvpn enabled.

Impact

An unauthenticated remote attacker can execute arbitrary code with full control of the appliance, or force a reload that disrupts all traffic through it. Full device compromise can expose VPN credentials, configurations and traffic handled by the firewall.

Attack surface

Reached over the network via the webvpn interface; the CVSS vector shows no privileges and no user interaction required. Only devices with the webvpn feature enabled are exposed.

Exploitation

Public exploit code is referenced (Exploit-DB 43986 and a Pastebin entry), and EPSS is very high at 0.8678 (99.7th percentile), though the CVE is not listed in CISA KEV.

What to do

  • Apply the Cisco ASA/FTD software update from advisory cisco-sa-20180129-asa1 immediately.
  • If patching cannot be done at once, disable the webvpn feature on internet-facing interfaces.
  • Restrict management and VPN access to trusted source addresses where operationally possible.
  • Monitor ASA/FTD for unexpected reloads and treat them as possible exploitation attempts.
  • Review ASA/FTD configurations and logs for signs of compromise after any exposure window.

Detection

  • Alert on unexpected ASA/FTD reloads or crash/restart events, especially on webvpn-enabled devices.
  • Inspect webvpn/HTTPS traffic for malformed or anomalous XML POST bodies targeting the VPN interface.
  • Correlate IDS/IPS signatures for CVE-2018-0101 with ASA/FTD syslog events.
  • Hunt for post-exploitation indicators such as new local accounts, config changes or outbound connections from the appliance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0101 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2018-0101), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.