CVE-2005-3788
Summary
| CVE | CVE-2005-3788 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-11-24 11:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Race condition in Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), and 7.0(4), when running with an Active/Standby configuration and when the failover LAN interface fails, allows remote attackers to cause a denial of service (standby firewall failure) by sending spoofed ARP responses from an IP address of an active firewall, which prevents the standby firewall from becoming active, aka "failover denial of service." |
Risk And Classification
Primary CVSS: v2.0 5.4 from [email protected]
AV:N/AC:H/Au:N/C:N/I:N/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:H/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Adaptive Security Appliance Software | 7.0\(0\) | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance Software | 7.0\(2\) | All | All | All |
| Operating System | Cisco | Adaptive Security Appliance Software | 7.0\(4\) | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| '[ADVISORY] CISCO ASA Failover DoS Vulnerability' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityTracker.com Archives - Cisco Adaptive Security Appliance Failover Bug Lets Remote Users Deny Service in Certain Conditions | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Vendor Advisory |
| Cisco Adaptive Security Applicance Failover Testing Denial of Service Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CISCO ASA Failover DoS Vulnerability - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Secunia - Advisories - Cisco ASA Failover Denial of Service Weakness | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 'RE: [ADVISORY] CISCO ASA Failover DoS Vulnerability' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.