CVE detail

CVE-2019-1873 — CVE-2019-1873

Published 2019-07-10 · Modified 2026-06-17 · Vendor cisco · Product asa_5506-x_firmware · Source nvd
HIGH
severity
CVSS-derived band
8.6
CVSS v3
0–10 scale
0.0246
EPSS probability
exploitation probability, 30d
83.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reboot unexpectedly. The vulnerability is due to incomplete input validation of a Secure Sockets Layer (SSL) or Transport Layer Security (TLS) ingress packet header. An attacker could exploit this vulnerability by sending a crafted TLS/SSL packet to an interface on the targeted device. An exploit could allow the attacker to cause the device to reload, which will result in a denial of service (DoS) condition. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability affects systems configured in routed and transparent firewall m

Remediation

ProductVulnerable rangeFixed versionAdvisory
Cisco Cisco Adaptive Security Appliance (ASA) Software>=unspecified<9.10.1.229.10.1.22advisory ↗
Cisco Cisco Adaptive Security Appliance (ASA) Software>=unspecified<9.12.29.12.2advisory ↗
Cisco Cisco Adaptive Security Appliance (ASA) Software>=unspecified<9.4.4.369.4.4.36advisory ↗
Cisco Cisco Adaptive Security Appliance (ASA) Software>=unspecified<9.6.4.299.6.4.29advisory ↗
Cisco Cisco Adaptive Security Appliance (ASA) Software>=unspecified<9.8.4.39.8.4.3advisory ↗
Cisco Cisco Adaptive Security Appliance (ASA) Software>=unspecified<9.9.2.529.9.2.52advisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.