Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:CISCO:ASA-CIFS-OF

Severity

Major

Recommended

No

Category

HTTP

Keywords

Cisco ASA Clientless SSL VPN Common Internet Filesystem Heap Overflow

Release Date

2020/06/10

Update Number

3289

Supported Platforms

idp-5.1+, srx-12.1+, srx-branch-12.1+, vsrx-15.1+, vsrx3bsd-18.2+

HTTP: Cisco ASA Clientless SSL VPN Common Internet Filesystem Heap Overflow


This signature detects attempts to exploit a known vulnerability against Cisco ASA Clientless. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the Cisco ASA Clientless.

Extended Description

A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases 9.0-9.6, could allow an authenticated, remote attacker to cause a heap overflow. The vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by sending a crafted URL to the affected system. An exploit could allow the remote attacker to cause a reload of the affected system or potentially execute code. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability affects systems configured in routed firewall mode only and in single or multiple context mode. This vulnerability can be triggered by IPv4 or IPv6 traffic. A valid TCP connection is needed to perform the attack. The attacker needs to have valid credentials to log in to the Clientless SSL VPN portal. Vulnerable Cisco ASA Software running on the following products may be affected by this vulnerability: Cisco ASA 5500 Series Adaptive Security Appliances, Cisco ASA 5500-X Series Next-Generation Firewalls, Cisco Adaptive Security Virtual Appliance (ASAv), Cisco ASA for Firepower 9300 Series, Cisco ASA for Firepower 4100 Series. Cisco Bug IDs: CSCvc23838.

Affected Products

  • Cisco adaptive_security_appliance_software 7.0.1
  • Cisco adaptive_security_appliance_software 7.0.1.4
  • Cisco adaptive_security_appliance_software 7.0.2
  • Cisco adaptive_security_appliance_software 7.0.3
  • Cisco adaptive_security_appliance_software 7.0.4
  • Cisco adaptive_security_appliance_software 7.0.4.2
  • Cisco adaptive_security_appliance_software 7.0.5
  • Cisco adaptive_security_appliance_software 7.0.5.12
  • Cisco adaptive_security_appliance_software 7.0.6
  • Cisco adaptive_security_appliance_software 7.0.6.18
  • Cisco adaptive_security_appliance_software 7.0.6.22
  • Cisco adaptive_security_appliance_software 7.0.6.26
  • Cisco adaptive_security_appliance_software 7.0.6.29
  • Cisco adaptive_security_appliance_software 7.0.6.32
  • Cisco adaptive_security_appliance_software 7.0.6.4
  • Cisco adaptive_security_appliance_software 7.0.6.8
  • Cisco adaptive_security_appliance_software 7.0.7
  • Cisco adaptive_security_appliance_software 7.0.7.1
  • Cisco adaptive_security_appliance_software 7.0.7.12
  • Cisco adaptive_security_appliance_software 7.0.7.4
  • Cisco adaptive_security_appliance_software 7.0.7.9
  • Cisco adaptive_security_appliance_software 7.0.8
  • Cisco adaptive_security_appliance_software 7.0.8.12
  • Cisco adaptive_security_appliance_software 7.0.8.13
  • Cisco adaptive_security_appliance_software 7.0.8.2
  • Cisco adaptive_security_appliance_software 7.0.8.8
  • Cisco adaptive_security_appliance_software 7.1.2
  • Cisco adaptive_security_appliance_software 7.1.2.16
  • Cisco adaptive_security_appliance_software 7.1.2.20
  • Cisco adaptive_security_appliance_software 7.1.2.24
  • Cisco adaptive_security_appliance_software 7.1.2.28
  • Cisco adaptive_security_appliance_software 7.1.2.38
  • Cisco adaptive_security_appliance_software 7.1.2.42
  • Cisco adaptive_security_appliance_software 7.1.2.46
  • Cisco adaptive_security_appliance_software 7.1.2.49
  • Cisco adaptive_security_appliance_software 7.1.2.53
  • Cisco adaptive_security_appliance_software 7.1.2.61
  • Cisco adaptive_security_appliance_software 7.1.2.64
  • Cisco adaptive_security_appliance_software 7.1.2.72
  • Cisco adaptive_security_appliance_software 7.1.2.81
  • Cisco adaptive_security_appliance_software 7.2.1
  • Cisco adaptive_security_appliance_software 7.2.1.13
  • Cisco adaptive_security_appliance_software 7.2.1.19
  • Cisco adaptive_security_appliance_software 7.2.1.24
  • Cisco adaptive_security_appliance_software 7.2.1.9
  • Cisco adaptive_security_appliance_software 7.2.2
  • Cisco adaptive_security_appliance_software 7.2.2.10
  • Cisco adaptive_security_appliance_software 7.2.2.14
  • Cisco adaptive_security_appliance_software 7.2.2.18
  • Cisco adaptive_security_appliance_software 7.2.2.19
  • Cisco adaptive_security_appliance_software 7.2.2.22
  • Cisco adaptive_security_appliance_software 7.2.2.34
  • Cisco adaptive_security_appliance_software 7.2.2.6
  • Cisco adaptive_security_appliance_software 7.2.3
  • Cisco adaptive_security_appliance_software 7.2.3.1
  • Cisco adaptive_security_appliance_software 7.2.3.12
  • Cisco adaptive_security_appliance_software 7.2.3.16
  • Cisco adaptive_security_appliance_software 7.2.4
  • Cisco adaptive_security_appliance_software 7.2.4.18
  • Cisco adaptive_security_appliance_software 7.2.4.25
  • Cisco adaptive_security_appliance_software 7.2.4.27
  • Cisco adaptive_security_appliance_software 7.2.4.30
  • Cisco adaptive_security_appliance_software 7.2.4.33
  • Cisco adaptive_security_appliance_software 7.2.4.6
  • Cisco adaptive_security_appliance_software 7.2.4.9
  • Cisco adaptive_security_appliance_software 7.2.5
  • Cisco adaptive_security_appliance_software 7.2.5.10
  • Cisco adaptive_security_appliance_software 7.2.5.12
  • Cisco adaptive_security_appliance_software 7.2.5.16
  • Cisco adaptive_security_appliance_software 7.2.5.2
  • Cisco adaptive_security_appliance_software 7.2.5.4
  • Cisco adaptive_security_appliance_software 7.2.5.7
  • Cisco adaptive_security_appliance_software 7.2.5.8
  • Cisco adaptive_security_appliance_software 8.0.1.2
  • Cisco adaptive_security_appliance_software 8.0.2
  • Cisco adaptive_security_appliance_software 8.0.2.11
  • Cisco adaptive_security_appliance_software 8.0.2.15
  • Cisco adaptive_security_appliance_software 8.0.3
  • Cisco adaptive_security_appliance_software 8.0.3.12
  • Cisco adaptive_security_appliance_software 8.0.3.19
  • Cisco adaptive_security_appliance_software 8.0.3.6
  • Cisco adaptive_security_appliance_software 8.0.4
  • Cisco adaptive_security_appliance_software 8.0.4.16
  • Cisco adaptive_security_appliance_software 8.0.4.23
  • Cisco adaptive_security_appliance_software 8.0.4.25
  • Cisco adaptive_security_appliance_software 8.0.4.28
  • Cisco adaptive_security_appliance_software 8.0.4.3
  • Cisco adaptive_security_appliance_software 8.0.4.31
  • Cisco adaptive_security_appliance_software 8.0.4.32
  • Cisco adaptive_security_appliance_software 8.0.4.33
  • Cisco adaptive_security_appliance_software 8.0.4.9
  • Cisco adaptive_security_appliance_software 8.0.5
  • Cisco adaptive_security_appliance_software 8.0.5.20
  • Cisco adaptive_security_appliance_software 8.0.5.23
  • Cisco adaptive_security_appliance_software 8.0.5.25
  • Cisco adaptive_security_appliance_software 8.0.5.27
  • Cisco adaptive_security_appliance_software 8.0.5.28
  • Cisco adaptive_security_appliance_software 8.0.5.31
  • Cisco adaptive_security_appliance_software 8.1.0.104
  • Cisco adaptive_security_appliance_software 8.1.1
  • Cisco adaptive_security_appliance_software 8.1.1.6
  • Cisco adaptive_security_appliance_software 8.1.2
  • Cisco adaptive_security_appliance_software 8.1.2.13
  • Cisco adaptive_security_appliance_software 8.1.2.15
  • Cisco adaptive_security_appliance_software 8.1.2.16
  • Cisco adaptive_security_appliance_software 8.1.2.19
  • Cisco adaptive_security_appliance_software 8.1.2.23
  • Cisco adaptive_security_appliance_software 8.1.2.24
  • Cisco adaptive_security_appliance_software 8.1.2.49
  • Cisco adaptive_security_appliance_software 8.1.2.50
  • Cisco adaptive_security_appliance_software 8.1.2.55
  • Cisco adaptive_security_appliance_software 8.1.2.56
  • Cisco adaptive_security_appliance_software 8.2.0.45
  • Cisco adaptive_security_appliance_software 8.2.1
  • Cisco adaptive_security_appliance_software 8.2.1.11
  • Cisco adaptive_security_appliance_software 8.2.2
  • Cisco adaptive_security_appliance_software 8.2.2.10
  • Cisco adaptive_security_appliance_software 8.2.2.12
  • Cisco adaptive_security_appliance_software 8.2.2.16
  • Cisco adaptive_security_appliance_software 8.2.2.17
  • Cisco adaptive_security_appliance_software 8.2.2.9
  • Cisco adaptive_security_appliance_software 8.2.3
  • Cisco adaptive_security_appliance_software 8.2.4
  • Cisco adaptive_security_appliance_software 8.2.4.1
  • Cisco adaptive_security_appliance_software 8.2.4.4
  • Cisco adaptive_security_appliance_software 8.2.5
  • Cisco adaptive_security_appliance_software 8.2.5.13
  • Cisco adaptive_security_appliance_software 8.2.5.22
  • Cisco adaptive_security_appliance_software 8.2.5.26
  • Cisco adaptive_security_appliance_software 8.2.5.33
  • Cisco adaptive_security_appliance_software 8.2.5.40
  • Cisco adaptive_security_appliance_software 8.2.5.41
  • Cisco adaptive_security_appliance_software 8.2.5.46
  • Cisco adaptive_security_appliance_software 8.2.5.48
  • Cisco adaptive_security_appliance_software 8.2.5.50
  • Cisco adaptive_security_appliance_software 8.2.5.52
  • Cisco adaptive_security_appliance_software 8.2.5.55
  • Cisco adaptive_security_appliance_software 8.2.5.57
  • Cisco adaptive_security_appliance_software 8.2.5.59
  • Cisco adaptive_security_appliance_software 8.3.1
  • Cisco adaptive_security_appliance_software 8.3.1.1
  • Cisco adaptive_security_appliance_software 8.3.1.4
  • Cisco adaptive_security_appliance_software 8.3.1.6
  • Cisco adaptive_security_appliance_software 8.3.2
  • Cisco adaptive_security_appliance_software 8.3.2.13
  • Cisco adaptive_security_appliance_software 8.3.2.23
  • Cisco adaptive_security_appliance_software 8.3.2.25
  • Cisco adaptive_security_appliance_software 8.3.2.31
  • Cisco adaptive_security_appliance_software 8.3.2.33
  • Cisco adaptive_security_appliance_software 8.3.2.34
  • Cisco adaptive_security_appliance_software 8.3.2.37
  • Cisco adaptive_security_appliance_software 8.3.2.39
  • Cisco adaptive_security_appliance_software 8.3.2.4
  • Cisco adaptive_security_appliance_software 8.3.2.40
  • Cisco adaptive_security_appliance_software 8.3.2.41
  • Cisco adaptive_security_appliance_software 8.3.2.44
  • Cisco adaptive_security_appliance_software 8.4.0
  • Cisco adaptive_security_appliance_software 8.4.1
  • Cisco adaptive_security_appliance_software 8.4.1.11
  • Cisco adaptive_security_appliance_software 8.4.1.3
  • Cisco adaptive_security_appliance_software 8.4.2
  • Cisco adaptive_security_appliance_software 8.4.2.1
  • Cisco adaptive_security_appliance_software 8.4.2.8
  • Cisco adaptive_security_appliance_software 8.4.3
  • Cisco adaptive_security_appliance_software 8.4.3.8
  • Cisco adaptive_security_appliance_software 8.4.3.9
  • Cisco adaptive_security_appliance_software 8.4.4
  • Cisco adaptive_security_appliance_software 8.4.4.1
  • Cisco adaptive_security_appliance_software 8.4.4.3
  • Cisco adaptive_security_appliance_software 8.4.4.5
  • Cisco adaptive_security_appliance_software 8.4.4.9
  • Cisco adaptive_security_appliance_software 8.4.5
  • Cisco adaptive_security_appliance_software 8.4.5.6
  • Cisco adaptive_security_appliance_software 8.4.6
  • Cisco adaptive_security_appliance_software 8.4.7
  • Cisco adaptive_security_appliance_software 8.4.7.15
  • Cisco adaptive_security_appliance_software 8.4.7.22
  • Cisco adaptive_security_appliance_software 8.4.7.23
  • Cisco adaptive_security_appliance_software 8.4.7.26
  • Cisco adaptive_security_appliance_software 8.4.7.28
  • Cisco adaptive_security_appliance_software 8.4.7.29
  • Cisco adaptive_security_appliance_software 8.4.7.3
  • Cisco adaptive_security_appliance_software 8.5.1
  • Cisco adaptive_security_appliance_software 8.5.1.1
  • Cisco adaptive_security_appliance_software 8.5.1.14
  • Cisco adaptive_security_appliance_software 8.5.1.17
  • Cisco adaptive_security_appliance_software 8.5.1.18
  • Cisco adaptive_security_appliance_software 8.5.1.19
  • Cisco adaptive_security_appliance_software 8.5.1.21
  • Cisco adaptive_security_appliance_software 8.5.1.24
  • Cisco adaptive_security_appliance_software 8.5.1.6
  • Cisco adaptive_security_appliance_software 8.5.1.7
  • Cisco adaptive_security_appliance_software 8.6.1
  • Cisco adaptive_security_appliance_software 8.6.1.1
  • Cisco adaptive_security_appliance_software 8.6.1.10
  • Cisco adaptive_security_appliance_software 8.6.1.12
  • Cisco adaptive_security_appliance_software 8.6.1.13
  • Cisco adaptive_security_appliance_software 8.6.1.14
  • Cisco adaptive_security_appliance_software 8.6.1.17
  • Cisco adaptive_security_appliance_software 8.6.1.2
  • Cisco adaptive_security_appliance_software 8.6.1.5
  • Cisco adaptive_security_appliance_software 8.7.1
  • Cisco adaptive_security_appliance_software 8.7.1.1
  • Cisco adaptive_security_appliance_software 8.7.1.11
  • Cisco adaptive_security_appliance_software 8.7.1.13
  • Cisco adaptive_security_appliance_software 8.7.1.16
  • Cisco adaptive_security_appliance_software 8.7.1.17
  • Cisco adaptive_security_appliance_software 8.7.1.3
  • Cisco adaptive_security_appliance_software 8.7.1.4
  • Cisco adaptive_security_appliance_software 8.7.1.7
  • Cisco adaptive_security_appliance_software 8.7.1.8
  • Cisco adaptive_security_appliance_software 9.0.1
  • Cisco adaptive_security_appliance_software 9.0.2
  • Cisco adaptive_security_appliance_software 9.0.2.10
  • Cisco adaptive_security_appliance_software 9.0.3
  • Cisco adaptive_security_appliance_software 9.0.3.6
  • Cisco adaptive_security_appliance_software 9.0.3.8
  • Cisco adaptive_security_appliance_software 9.0.4
  • Cisco adaptive_security_appliance_software 9.0.4.1
  • Cisco adaptive_security_appliance_software 9.0.4.17
  • Cisco adaptive_security_appliance_software 9.0.4.20
  • Cisco adaptive_security_appliance_software 9.0.4.24
  • Cisco adaptive_security_appliance_software 9.0.4.26
  • Cisco adaptive_security_appliance_software 9.0.4.29
  • Cisco adaptive_security_appliance_software 9.0.4.33
  • Cisco adaptive_security_appliance_software 9.0.4.35
  • Cisco adaptive_security_appliance_software 9.0.4.37
  • Cisco adaptive_security_appliance_software 9.0.4.40
  • Cisco adaptive_security_appliance_software 9.0.4.42
  • Cisco adaptive_security_appliance_software 9.0.4.5
  • Cisco adaptive_security_appliance_software 9.0.4.7
  • Cisco adaptive_security_appliance_software 9.1.1
  • Cisco adaptive_security_appliance_software 9.1.1.4
  • Cisco adaptive_security_appliance_software 9.1.2
  • Cisco adaptive_security_appliance_software 9.1.2.8
  • Cisco adaptive_security_appliance_software 9.1.3
  • Cisco adaptive_security_appliance_software 9.1.3.2
  • Cisco adaptive_security_appliance_software 9.1.4
  • Cisco adaptive_security_appliance_software 9.1.4.5
  • Cisco adaptive_security_appliance_software 9.1.5
  • Cisco adaptive_security_appliance_software 9.1.5.10
  • Cisco adaptive_security_appliance_software 9.1.5.12
  • Cisco adaptive_security_appliance_software 9.1.5.15
  • Cisco adaptive_security_appliance_software 9.1.5.21
  • Cisco adaptive_security_appliance_software 9.1.6
  • Cisco adaptive_security_appliance_software 9.1.6.1
  • Cisco adaptive_security_appliance_software 9.1.6.10
  • Cisco adaptive_security_appliance_software 9.1.6.4
  • Cisco adaptive_security_appliance_software 9.1.6.6
  • Cisco adaptive_security_appliance_software 9.1.6.8
  • Cisco adaptive_security_appliance_software 9.1(7)11
  • Cisco adaptive_security_appliance_software 9.1(7)12
  • Cisco adaptive_security_appliance_software 9.1(7)4
  • Cisco adaptive_security_appliance_software 9.1(7)6
  • Cisco adaptive_security_appliance_software 9.1(7)7
  • Cisco adaptive_security_appliance_software 9.1(7)9
  • Cisco adaptive_security_appliance_software 9.2(0.0)
  • Cisco adaptive_security_appliance_software 9.2(0.104)
  • Cisco adaptive_security_appliance_software 9.2.1
  • Cisco adaptive_security_appliance_software 9.2.2
  • Cisco adaptive_security_appliance_software 9.2.2.4
  • Cisco adaptive_security_appliance_software 9.2.2.7
  • Cisco adaptive_security_appliance_software 9.2.2.8
  • Cisco adaptive_security_appliance_software 9.2.3
  • Cisco adaptive_security_appliance_software 9.2(3.1)
  • Cisco adaptive_security_appliance_software 9.2.3.3
  • Cisco adaptive_security_appliance_software 9.2.3.4
  • Cisco adaptive_security_appliance_software 9.2.4
  • Cisco adaptive_security_appliance_software 9.2.4.10
  • Cisco adaptive_security_appliance_software 9.2.4.13
  • Cisco adaptive_security_appliance_software 9.2.4.14
  • Cisco adaptive_security_appliance_software 9.2.4.16
  • Cisco adaptive_security_appliance_software 9.2.4.17
  • Cisco adaptive_security_appliance_software 9.2.4.18
  • Cisco adaptive_security_appliance_software 9.2.4.19
  • Cisco adaptive_security_appliance_software 9.2.4.2
  • Cisco adaptive_security_appliance_software 9.2.4.4
  • Cisco adaptive_security_appliance_software 9.2.4.8
  • Cisco adaptive_security_appliance_software 9.3.1
  • Cisco adaptive_security_appliance_software 9.3.1.1
  • Cisco adaptive_security_appliance_software 9.3(1.105)
  • Cisco adaptive_security_appliance_software 9.3(1.50)
  • Cisco adaptive_security_appliance_software 9.3.2
  • Cisco adaptive_security_appliance_software 9.3(2.100)
  • Cisco adaptive_security_appliance_software 9.3.2.2
  • Cisco adaptive_security_appliance_software 9.3(2.243)
  • Cisco adaptive_security_appliance_software 9.3.3
  • Cisco adaptive_security_appliance_software 9.3.3.1
  • Cisco adaptive_security_appliance_software 9.3.3.10
  • Cisco adaptive_security_appliance_software 9.3.3.11
  • Cisco adaptive_security_appliance_software 9.3.3.2
  • Cisco adaptive_security_appliance_software 9.3.3.5
  • Cisco adaptive_security_appliance_software 9.3.3.6
  • Cisco adaptive_security_appliance_software 9.3.3.9
  • Cisco adaptive_security_appliance_software 9.3.5
  • Cisco adaptive_security_appliance_software 9.4.0.115
  • Cisco adaptive_security_appliance_software 9.4.1
  • Cisco adaptive_security_appliance_software 9.4.1.1
  • Cisco adaptive_security_appliance_software 9.4.1.2
  • Cisco adaptive_security_appliance_software 9.4.1.3
  • Cisco adaptive_security_appliance_software 9.4.1.5
  • Cisco adaptive_security_appliance_software 9.4.2
  • Cisco adaptive_security_appliance_software 9.4.2.3
  • Cisco adaptive_security_appliance_software 9.4.3
  • Cisco adaptive_security_appliance_software 9.4.3.3
  • Cisco adaptive_security_appliance_software 9.4.3.4
  • Cisco adaptive_security_appliance_software 9.5.1
  • Cisco adaptive_security_appliance_software 9.5.2
  • Cisco adaptive_security_appliance_software 9.5.2.10
  • Cisco adaptive_security_appliance_software 9.5.2.14
  • Cisco adaptive_security_appliance_software 9.5.2.6
  • Cisco adaptive_security_appliance_software 9.5.3
  • Cisco adaptive_security_appliance_software 9.5.3.1
  • Cisco adaptive_security_appliance_software 9.5.3.2
  • Cisco adaptive_security_appliance_software 9.5.3.3
  • Cisco adaptive_security_appliance_software 9.5.3.6
  • Cisco adaptive_security_appliance_software 9.5.3.7
  • Cisco adaptive_security_appliance_software 9.6.1.10
  • Cisco adaptive_security_appliance_software 9.6.1.5
  • Cisco adaptive_security_appliance_software 9.6.2
  • Cisco adaptive_security_appliance_software 9.6.2.1
  • Cisco adaptive_security_appliance_software 9.6.2.2
  • Cisco adaptive_security_appliance_software 9.6.2.3
  • Cisco adaptive_security_appliance_software 9.6.2.7

References

  • BugTraq: 96161
  • CVE: CVE-2017-3807

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out