Executive Summary
Summary | |
---|---|
Title | Cisco Adaptive Security Appliance Software DHCPv6 Relay Denial of Service Vulnerability |
Informations | |||
---|---|---|---|
Name | cisco-sa-20160420-asa-dhcpv6 | First vendor Publication | 2016-04-20 |
Vendor | Cisco | Last vendor Modification | 2016-04-20 |
Severity (Vendor) | N/A | Revision | 1.0 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.8 | Attack Range | Network |
Cvss Impact Score | 6.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A vulnerability in the DHCPv6 relay feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient validation of DHCPv6 packets. An attacker could exploit this vulnerability by sending crafted DHCPv6 packets to an affected device, resulting in a denial of service (DoS) condition. This vulnerability affects systems configured in routed firewall mode and in single or multiple context mode. Cisco ASA Software is affected by this vulnerability only if the software is configured with the DHCPv6 relay feature. The vulnerability is triggered only by IPv6 traffic. This vulnerability affects Cisco ASA Software release 9.4.1 only. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160420-asa-dhcpv6 BEGIN PGP SIGNATURE Version: GnuPG/MacGPG2 v2 Comment: GPGTools - https://gpgtools.org iQIcBAEBCgAGBQJXF3DCAAoJEK89gD3EAJB5pscP/A82fZg0GxmGGZlQR0YGSC/F M1jaBmDHh1/Hofa0Wi1jTsUiEQBFRh/NzrW7PAF1xxz8oFA09l050HOXc1uqbwyl kFZn5/gnNOOl8FJ7E7Uq3yB1690XelnFMV5T86tiFTssmAHJWjtc/H/F/C8pate6 yNxm/ns+XJKODkgFId8WtXSiRm2TLSc7KaLSb4CiAy8IZzKyu1jXE7CNWvzdfi+y FdBR8nVdqZDW0VTJ6dVzYcWls3+wbcJAesZtAWJS9RhbV5hWlumOVmbJe78wMff4 ZBZ/qy8yS3xSqA2qjNbPgszJuhTwudNKAagOOpkPUxze36s5J3Z+LKOaPGHKWgiD rK/WVa7M2nD8N92NsOt/VQQ8D3KPW+iZ4UN4heQ8A/JC7/4OAc8bKt1cwkpspslX /r2ihH0grTksybKjTGwHus0c4fWB5rKGeVZagb8rEiYi0hbGAblruUr6ovFlhA0U 2gpgwoXtQSj0DZLzPRfqxTEAZ2reC+Ny6TqbW1qokl43sWxguNW9lfJPxU1G1ub2 vIKwxz+Utq3xWQ9wvSDQ8lT3mJTj+Mu4KQNC6YEzd6kxJCf8z6Bseg2JMJyTlMRh FADKRiamRkfQhUa8C6J4DQa4PFIQb7oVbaNBKuSKZd77mGM/+6L1mXF1/TGlnLgH VfzhOiSQd2rx3zyxsjG1 =nIGk END PGP SIGNATURE _______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com |
Original Source
Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...) |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-399 | Resource Management Errors |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 |
Snort® IPS/IDS
Date | Description |
---|---|
2016-03-14 | Cisco ASA DHCPv6 relay solicit denial of service attempt RuleID : 36558 - Revision : 2 - Type : SERVER-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2016-04-26 | Name : The remote device is missing a vendor-supplied security patch. File : cisco-sa-20160420-asa-dhcpv6.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2016-04-28 13:28:16 |
|
2016-04-27 09:42:07 |
|
2016-04-20 21:25:45 |
|