Rockwell Automation Allen-Bradley Stratix 5950 Improper Certificate Validation (CVE-2018-0227)

high Tenable OT Security Plugin ID 506145

Synopsis

The remote OT asset is affected by a vulnerability.

Description

A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN connection and bypass certain SSL certificate verification steps. The vulnerability is due to incorrect verification of the SSL Client Certificate. An attacker could exploit this vulnerability by connecting to the ASA VPN without a proper private key and certificate pair. A successful exploit could allow the attacker to establish an SSL VPN connection to the ASA when the connection should have been rejected. This vulnerability affects Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Software that is running on the following Cisco products: 3000 Series Industrial Security Appliances (ISA), ASA 5500 Series Adaptive Security Appliances, ASA 5500-X Series Next-Generation Firewalls, ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers, Adaptive Security Virtual Appliances (ASAv), Firepower 4110 Security Appliances, Firepower 9300 ASA Security Modules. Cisco Bug IDs: CSCvg40155.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

The following text was originally created by the Cybersecurity and Infrastructure Security Agency (CISA). The original can be found at CISA.gov.

Rockwell Automation will inform users of updated firmware as soon as it is available. Rockwell Automation recommends that users using affected devices apply the following risk mitigation strategies:

- CVE-2018-0228 — The ASA and FTD configuration commands—set connection per-client-embryonic-max (TCP) and set connection per-client-max (TCP, UDP, and Stream Control Transmission Protocol [SCTP])—can be configured to limit the number of connection requests allowed. Using these configuration parameters can reduce the number of connections and greatly reduce the impact of the DoS attack.
- CVE-2018-0227 — No workarounds available
- CVE-2018-0231 — No workarounds available
- CVE-2018-0240 — No workarounds available
- CVE-2018-0296 — Cisco has released Snort Rule 46897

For additional information please see the Rockwell Automation security notification at (login required):
https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1073860

Additionally the Cisco advisories can be found at the following links:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa2

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa1

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa3

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180418-asa_inspect

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-asaftd

See Also

https://ics-cert.us-cert.gov/advisories/ICSA-18-184-01

http://www.nessus.org/u?3022fd51

http://www.securityfocus.com/bid/104018

http://www.securitytracker.com/id/1040723

Plugin Details

Severity: High

ID: 506145

File Name: tenable_ot_cisco_CVE-2018-0227.nasl

Version: 1.2

Type: Remote

Family: Tenable.ot

Published: 10/6/2026

Updated: 10/6/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2018-0227

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Vulnerability Information

CPE: cpe:/o:cisco:adaptive_security_appliance_software:9.4.3.1, cpe:/o:cisco:adaptive_security_appliance_software:9.4.3.2, cpe:/o:cisco:adaptive_security_appliance_software:9.5.2.7, cpe:/o:cisco:adaptive_security_appliance_software:9.5.2.8, cpe:/o:cisco:adaptive_security_appliance_software:9

Required KB Items: Tenable.ot/Cisco

Patch Publication Date: 4/19/2018

Vulnerability Publication Date: 4/19/2018

Reference Information

CVE: CVE-2018-0227

CWE: 295