high Known exploitedREV. 01
CVE-2018-0296Cisco ASA — Unauthenticated Crash and File Read
Cisco's Adaptive Security Appliance (ASA) firewalls can be reloaded by an unauthenticated request to their web interface, and on some releases the same flaw reads files off the device.
Read the risk
THE VITAL STATS- CVSS score
- 7.5/ 10 CVSS v3.1
- EPSS probability
- 100% Likelihood of exploitation
- Attack complexity
- Low Conditions needed to exploit
- Known exploited
- Yes — CISA KEV
- CVE published
- 2018-06-07
- Added to KEV
- 2021-11-03
- Exploit published
- Yes
- Confidence
- high
- Kill chain
- discovery
- MITRE ATT&CK
- T1190, T1083
- Severity
- high
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attacker needsNetwork access to the appliance web interface
Behind the card
5 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02CISACISA Known Exploited Vulnerabilities catalogcisa.gov
- 03Vendor advisorytools.cisco.comtools.cisco.com
- 04Exploitpacketstormsecurity.compacketstormsecurity.com
- 05Exploitexploit-db.comexploit-db.com
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_at | nvd.nist.gov | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| exploitation.known_exploited, exploitation.kev_added | cisa.gov | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| epss | api.first.org | 2026-08-07 | scrty-crds-pipeline/0.1 | high |
| title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisites | nvd.nist.gov | 2026-08-07 | claude-code | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.