A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability is due to insufficient error checking when processing SAML messages. An attacker could exploit this vulnerability by sending crafted SAML messages to the SAML service. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Adaptive_security_appliance_software | Cisco | 9.12.1 (including) | 9.16.4.85 (excluding) |
| Adaptive_security_appliance_software | Cisco | 9.17.1 (including) | 9.18.4.66 (excluding) |
| Adaptive_security_appliance_software | Cisco | 9.19.1 (including) | 9.20.4 (excluding) |
| Adaptive_security_appliance_software | Cisco | 9.22.1.1 (including) | 9.22.2.4 (excluding) |
| Adaptive_security_appliance_software | Cisco | 9.23.1 (including) | 9.23.1.7 (excluding) |