Vulnerability record · CVE-2018-0296 · published 7 June 2018
CVE-2018-0296: Cisco ASA and FTD web interface path traversal and DoS
Cisco · Adaptive Security Appliance Software
The web interface of Cisco ASA and Firepower Threat Defense software fails to properly validate HTTP URLs, allowing crafted requests to trigger a device reload or, on some releases, unauthenticated disclosure of sensitive system information via directory traversal. Because the flaw is reachable over the network without credentials, it exposes internet-facing firewall and VPN appliances to both denial of service and information leakage.
Description
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
critical priorityIt is in CISA's Known Exploited Vulnerabilities catalog with public exploit code, a near-maximum EPSS score, and unauthenticated remote reachability against perimeter security devices.
What it is
The web interface of Cisco ASA and Firepower Threat Defense software fails to properly validate HTTP URLs, allowing crafted requests to trigger a device reload or, on some releases, unauthenticated disclosure of sensitive system information via directory traversal. Because the flaw is reachable over the network without credentials, it exposes internet-facing firewall and VPN appliances to both denial of service and information leakage.
Impact
An unauthenticated remote attacker can force an affected appliance to reload, causing a denial of service, or read sensitive system information from the device on certain software releases.
Attack surface
Reachable over the network through the ASA/FTD web interface via crafted HTTP requests on IPv4 or IPv6; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2021-11-03, public exploit code exists (Exploit-DB 44956 and Packet Storm), and EPSS scores it at roughly 0.999 probability in the 99.9th percentile.
What to do
- Apply the vendor updates referenced in Cisco advisory cisco-sa-20180606-asaftd as the primary fix.
- Restrict or disable HTTP/HTTPS management access on internet-facing interfaces and limit it to trusted management networks.
- Enforce the CISA KEV remediation due date of 2022-05-03 if not already completed.
- Monitor and log HTTP requests to the ASA/FTD web interface for traversal patterns and unexpected reloads.
- Verify device software versions against the Cisco advisory to confirm exposure before and after patching.
Detection
- Alert on HTTP requests to the ASA/FTD web interface containing directory traversal sequences such as ../ or encoded variants.
- Monitor device logs and syslog for unexpected reloads or crash/restart events on ASA and FTD appliances.
- Review web interface access logs for unauthenticated requests to paths outside expected management endpoints.
- Correlate spikes in HTTP requests to management interfaces with device availability changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0296 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-0296 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0296), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.