{"id":"CVE-2018-0231","title":"A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of th…","summary":"A vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of th…","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","cwe":["CWE-20","CWE-787"],"vendor":"cisco","product":"secure_firewall_threat_defense","affected":["adaptive_security_appliance_software = 9.8(1)","adaptive_security_appliance_software = 98.1(1.154)","secure_firewall_threat_defense >= 6.0, < 6.1.0.6","secure_firewall_threat_defense >= 6.2.1, < 6.2.2.1"],"patched":["secure_firewall_threat_defense 6.2.2.1"],"published":"2018-04-19","updated":"2026-08-11","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-0231","references":[{"url":"http://www.securitytracker.com/id/1040725","label":"psirt@cisco.com"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01","label":"psirt@cisco.com"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa3","label":"psirt@cisco.com"},{"url":"http://www.securitytracker.com/id/1040725","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa3","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.04132,"epssPercentile":0.90398,"ingestedAt":"2026-08-11T19:48:25.574Z","slug":"CVE-2018-0231","body":"## Overview\n\nA vulnerability in the Transport Layer Security (TLS) library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a malicious TLS message to an interface enabled for Secure Layer Socket (SSL) services on an affected device. Messages using SSL Version 3 (SSLv3) or SSL Version 2 (SSLv2) cannot be be used to exploit this vulnerability. An exploit could allow the attacker to cause a buffer underflow, triggering a crash on an affected device. This vulnerability affects Cisco ASA Software and Cisco FTD Software that is running on the following Cisco products: Adaptive Security Virtual Appliance (ASAv), Firepower Threat Defense Virtual (FTDv), Firepower 2100 Series Security Appliance. Cisco Bug IDs: CSCve18902, CSCve34335, CSCve38446.\n\n## Affected\n\n- `adaptive_security_appliance_software = 9.8(1)`\n- `adaptive_security_appliance_software = 98.1(1.154)`\n- `secure_firewall_threat_defense >= 6.0, < 6.1.0.6`\n- `secure_firewall_threat_defense >= 6.2.1, < 6.2.2.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `secure_firewall_threat_defense 6.2.2.1`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.3,"likelihood":0.8,"exploitation":0,"ransomware":0},"changes":[]}