Cisco PIX and ASA Appliance 'TTL Decrement' Denial of Service Vulnerability
BID:27418
Info
Cisco PIX and ASA Appliance 'TTL Decrement' Denial of Service Vulnerability
| Bugtraq ID: | 27418 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-0028 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2008 12:00AM |
| Updated: | Jan 24 2008 12:48AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Cisco PIX/ASA 8.0(2) Cisco PIX/ASA 8.0 Cisco PIX/ASA 7.2.(2.8) Cisco PIX/ASA 7.2.(2.7) Cisco PIX/ASA 7.2.(2.19) Cisco PIX/ASA 7.2.(2.17) Cisco PIX/ASA 7.2.(2.16) Cisco PIX/ASA 7.2(2.24) Cisco PIX/ASA 7.2(2.15) Cisco PIX/ASA 7.2(2.14) Cisco PIX/ASA 7.2(2.10) Cisco PIX/ASA 7.2(2) |
| Not Vulnerable: |
Cisco PIX/ASA 8.0(3) Cisco PIX/ASA 7.2(3)006 Cisco Firewall Services Module (FWSM) 0 |
Discussion
Cisco PIX and ASA Appliance 'TTL Decrement' Denial of Service Vulnerability
Multiple Cisco security appliances are prone to a denial-of-service vulnerability when the Time-To-Live (TTL) decrement feature is enabled for handling IP packets.
An attacker can exploit this issue to cause the affected devices to reload, denying service to legitimate users. Repeat attacks will result in a prolonged denial-of-service condition.
The following devices are affected:
Cisco PIX 500 Series Security Appliance
Cisco 5500 Series Adaptive Security Appliance (ASA)
Devices running software versions from 7.2(2) and up to 7.2(3)006 or 8.0(3) that have the TTL decrement feature enabled are vulnerable to this issue.
NOTE: The TTL decrement feature is not configured by default on the devices listed above. Devices that do not support the TTL decrement feature are not vulnerable.
Multiple Cisco security appliances are prone to a denial-of-service vulnerability when the Time-To-Live (TTL) decrement feature is enabled for handling IP packets.
An attacker can exploit this issue to cause the affected devices to reload, denying service to legitimate users. Repeat attacks will result in a prolonged denial-of-service condition.
The following devices are affected:
Cisco PIX 500 Series Security Appliance
Cisco 5500 Series Adaptive Security Appliance (ASA)
Devices running software versions from 7.2(2) and up to 7.2(3)006 or 8.0(3) that have the TTL decrement feature enabled are vulnerable to this issue.
NOTE: The TTL decrement feature is not configured by default on the devices listed above. Devices that do not support the TTL decrement feature are not vulnerable.
Exploit / POC
Cisco PIX and ASA Appliance 'TTL Decrement' Denial of Service Vulnerability
To exploit this issue, attackers can use readily available network utilities.
To exploit this issue, attackers can use readily available network utilities.
Solution / Fix
Cisco PIX and ASA Appliance 'TTL Decrement' Denial of Service Vulnerability
Solution:
The vendor released updates to address this issue. Please see the referenced advisory for more information.
Solution:
The vendor released updates to address this issue. Please see the referenced advisory for more information.
References
Cisco PIX and ASA Appliance 'TTL Decrement' Denial of Service Vulnerability
References:
References:
- Cisco Homepage (Cisco )
- TTL Expiry Attack Identification and Mitigation (Cisco Systems)
- Cisco Security Advisory: Cisco PIX and ASA Time-to-Live Vulnerability (Cisco Systems Product Security Incident Response Team
) - RE: Cisco Security Advisory: Cisco PIX and ASA Time-to-Live Vulnerability ("Eric Davis"
)