A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of LDAP packets sent to an affected device. An attacker could exploit these vulnerabilities by sending a crafted LDAP packet, using Basic Encoding Rules (BER), to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Adaptive Security Appliance Software
Subscribe
Asa 5505
Subscribe
Asa 5510
Subscribe
Asa 5512-x
Subscribe
Asa 5515-x
Subscribe
Asa 5520
Subscribe
Asa 5525-x
Subscribe
Asa 5540
Subscribe
Asa 5545-x
Subscribe
Asa 5550
Subscribe
Asa 5555-x
Subscribe
Asa 5580
Subscribe
Asa 5585-x
Subscribe
Firepower Threat Defense
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-10254 | A vulnerability in the implementation of the Lightweight Directory Access Protocol (LDAP) feature in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of LDAP packets sent to an affected device. An attacker could exploit these vulnerabilities by sending a crafted LDAP packet, using Basic Encoding Rules (BER), to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 21 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-21T19:35:18.270Z
Reserved: 2018-12-06T00:00:00
Link: CVE-2019-1697
Updated: 2024-08-04T18:28:41.125Z
Status : Modified
Published: 2019-05-03T16:29:00.240
Modified: 2024-11-21T04:37:07.460
Link: CVE-2019-1697
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD