Skip to main content

Cisco ASA and FTD DoS Vulnerability

A vulnerability has been discovered in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software that allows a remote attacker to cause a denial-of-service (DoS) in affected devices.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability has been discovered in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software that allows a remote attacker to cause a denial-of-service (DoS) in affected devices.

Threat details

The vulnerability is caused by mishandling of Session Initiation Protocol (SIP) traffic. An attacker can send crafted SIP requests at a high rate to cause the device to reboot or experience high CPU usage.

The SIP inspection engine is enabled by default in both the ASA and FTD software.


Remediation steps

Type Step

Cisco has not yet released updates to address this vulnerability. Users and administrators are encouraged to read the Cisco Security Advisory.

Administrators can check if the vulnerability is being actively exploited by checking the output of show conn port 5060, which would show large volumes of incomplete SIP connections. The output of show processes cpu-usage non-zero sorted would show a high CPU utilisation. When a device crashes and reloads, the output of show crashinfo would show an unknown abort of the DATAPATH thread. The Cisco Technical Assistance Centre can determine whether the crash was related to an exploit of this vulnerability.

Exploits can be mitigated by blocking traffic from the offending host. SIP inspection could also be disabled, however this will break SIP connections if they use Network Address Translation or if not all required ports are opened using Access Control Lists.

In some cases, malicious traffic has had the Sent-by Address set to the invalid value 0.0.0[.]0. Filtering can be applied on the Sent-by Address to prevent crashes from this type of traffic.


Last edited: 17 February 2020 12:39 pm