← Vulnerability feed

Vulnerability record · CVE-2018-0296 · published 7 June 2018

CVE-2018-0296: Cisco ASA and FTD web interface path traversal and DoS

Cisco · Adaptive Security Appliance Software

The web interface of Cisco ASA and Firepower Threat Defense software fails to properly validate HTTP URLs, allowing crafted requests to trigger a device reload or, on some releases, unauthenticated disclosure of sensitive system information via directory traversal. Because the flaw is reachable over the network without credentials, it exposes internet-facing firewall and VPN appliances to both denial of service and information leakage.

7.5 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 100% · top 0.1% CWE-20 · Improper input validationCWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
13References, 4 tagged exploit
11 Aug 2026Last modified by NVD

Description

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA's Known Exploited Vulnerabilities catalog with public exploit code, a near-maximum EPSS score, and unauthenticated remote reachability against perimeter security devices.

What it is

The web interface of Cisco ASA and Firepower Threat Defense software fails to properly validate HTTP URLs, allowing crafted requests to trigger a device reload or, on some releases, unauthenticated disclosure of sensitive system information via directory traversal. Because the flaw is reachable over the network without credentials, it exposes internet-facing firewall and VPN appliances to both denial of service and information leakage.

Impact

An unauthenticated remote attacker can force an affected appliance to reload, causing a denial of service, or read sensitive system information from the device on certain software releases.

Attack surface

Reachable over the network through the ASA/FTD web interface via crafted HTTP requests on IPv4 or IPv6; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2021-11-03, public exploit code exists (Exploit-DB 44956 and Packet Storm), and EPSS scores it at roughly 0.999 probability in the 99.9th percentile.

What to do

  • Apply the vendor updates referenced in Cisco advisory cisco-sa-20180606-asaftd as the primary fix.
  • Restrict or disable HTTP/HTTPS management access on internet-facing interfaces and limit it to trusted management networks.
  • Enforce the CISA KEV remediation due date of 2022-05-03 if not already completed.
  • Monitor and log HTTP requests to the ASA/FTD web interface for traversal patterns and unexpected reloads.
  • Verify device software versions against the Cisco advisory to confirm exposure before and after patching.

Detection

  • Alert on HTTP requests to the ASA/FTD web interface containing directory traversal sequences such as ../ or encoded variants.
  • Monitor device logs and syslog for unexpected reloads or crash/restart events on ASA and FTD appliances.
  • Review web interface access logs for unauthenticated requests to paths outside expected management endpoints.
  • Correlate spikes in HTTP requests to management interfaces with device availability changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-0296 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0296 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.1CVE-2023-20269Cisco ASA and FTD remote access VPN AAA separation flawCisco ASA and FTD remote access VPN features fail to properly separate AAA from the HTTPS management and site-to-site VPN features. An attacker can s…KEVEPSS 25%analysed8.8CVE-2016-6366Cisco ASA SNMP buffer overflow allows remote code executionCisco ASA, PIX and FWSM software through 9.4.2.3 contains a classic buffer overflow (CWE-120) reachable through crafted IPv4 SNMP packets. A remote a…KEVEPSS 88%analysed8.6CVE-2026-20349Cisco ASA and FTD SSL VPN HTTP request handling denial of serviceCisco Secure Firewall ASA and FTD software fail to properly check errors when processing HTTP requests in the Remote Access SSL VPN service. An unaut…KEVEPSS 1.0%analysed8.6CVE-2025-20362Cisco Secure Firewall ASA/FTD VPN web server missing authorizationThe VPN web server in Cisco Secure Firewall ASA and FTD software fails to properly validate user-supplied input in HTTP(S) requests, allowing access …KEVEPSS 87%analysed8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed7.8CVE-2016-6367Cisco ASA CLI command injection privilege escalationCisco ASA Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices mishandles invalid CLI commands, allowing command injection (CWE-77).…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2018-0296), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.