Rockwell Automation Allen-Bradley Stratix 5950 Improper Input Validation (CVE-2018-0296)

high Tenable OT Security Plugin ID 506154

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system information without authentication by using directory traversal techniques. The vulnerability is due to lack of proper input validation of the HTTP URL. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device.
An exploit could allow the attacker to cause a DoS condition or unauthenticated disclosure of information. This vulnerability applies to IPv4 and IPv6 HTTP traffic. This vulnerability affects Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliance (ISA), ASA 1000V Cloud Firewall, ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliance (ASAv), Firepower 2100 Series Security Appliance, Firepower 4100 Series Security Appliance, Firepower 9300 ASA Security Module, FTD Virtual (FTDv). Cisco Bug IDs: CSCvi16029.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

The following text was originally created by the Cybersecurity and Infrastructure Security Agency (CISA). The original can be found at CISA.gov.

Rockwell Automation will inform users of updated firmware as soon as it is available. Rockwell Automation recommends that users using affected devices apply the following risk mitigation strategies:

- CVE-2018-0228 — The ASA and FTD configuration commands—set connection per-client-embryonic-max (TCP) and set connection per-client-max (TCP, UDP, and Stream Control Transmission Protocol [SCTP])—can be configured to limit the number of connection requests allowed. Using these configuration parameters can reduce the number of connections and greatly reduce the impact of the DoS attack.
- CVE-2018-0227 — No workarounds available
- CVE-2018-0231 — No workarounds available
- CVE-2018-0240 — No workarounds available
- CVE-2018-0296 — Cisco has released Snort Rule 46897

For additional information please see the Rockwell Automation security notification at (login required):
https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1073860

Additionally the Cisco advisories can be found at the following links:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa2

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa1

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa3

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa_inspect

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-asaftd

See Also

https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01

https://www.exploit-db.com/exploits/44956/

http://www.nessus.org/u?43e5aa79

http://www.nessus.org/u?c235f451

http://www.nessus.org/u?c8591b08

http://www.securityfocus.com/bid/104612

http://www.securitytracker.com/id/1041076

Plugin Details

Severity: High

ID: 506154

File Name: tenable_ot_cisco_CVE-2018-0296.nasl

Version: 1.3

Type: Remote

Family: Tenable.ot

Published: 10/6/2026

Updated: 10/6/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 6

Percentile: 96.57

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2018-0296

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 7.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:cisco:adaptive_security_appliance_software:9

Required KB Items: Tenable.ot/Cisco

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/7/2018

Vulnerability Publication Date: 6/7/2018

CISA Known Exploited Vulnerability Due Dates: 5/3/2022

Reference Information

CVE: CVE-2018-0296

CWE: 20, 22