Cisco PIX and ASA Appliance IPv6 Denial of Service Vulnerability
BID:31863
Info
Cisco PIX and ASA Appliance IPv6 Denial of Service Vulnerability
| Bugtraq ID: | 31863 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-3816. |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2008 12:00AM |
| Updated: | Oct 22 2008 07:56PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Cisco PIX/ASA 7.2(4)9 Cisco PIX/ASA 7.2(4)10 |
| Not Vulnerable: |
Cisco PIX/ASA 7.2(4)11 |
Discussion
Cisco PIX and ASA Appliance IPv6 Denial of Service Vulnerability
Multiple Cisco security appliances are prone to a denial-of-service vulnerability when configured for IPv6.
An attacker can exploit this issue to cause the affected devices to reload, denying service to legitimate users. This issue is documented in Cisco Bug ID CSCsu11575.
The following devices are affected:
Cisco PIX Security Appliance
Cisco 5500 Series Adaptive Security Appliance (ASA)
Devices running software versions from 7.2(4)9 or 7.2(4)10 that have IPv6 enabled are vulnerable to this issue.
NOTE: IPv6 is not configured by default on the devices listed above. Devices that do not support the TTL decrement feature are not vulnerable.
Multiple Cisco security appliances are prone to a denial-of-service vulnerability when configured for IPv6.
An attacker can exploit this issue to cause the affected devices to reload, denying service to legitimate users. This issue is documented in Cisco Bug ID CSCsu11575.
The following devices are affected:
Cisco PIX Security Appliance
Cisco 5500 Series Adaptive Security Appliance (ASA)
Devices running software versions from 7.2(4)9 or 7.2(4)10 that have IPv6 enabled are vulnerable to this issue.
NOTE: IPv6 is not configured by default on the devices listed above. Devices that do not support the TTL decrement feature are not vulnerable.
Exploit / POC
Cisco PIX and ASA Appliance IPv6 Denial of Service Vulnerability
To exploit this issue, attackers can use readily available network utilities.
To exploit this issue, attackers can use readily available network utilities.
Solution / Fix
Cisco PIX and ASA Appliance IPv6 Denial of Service Vulnerability
Solution:
The vendor has released updates. Please see the referenced advisory for more information.
Solution:
The vendor has released updates. Please see the referenced advisory for more information.
References
Cisco PIX and ASA Appliance IPv6 Denial of Service Vulnerability
References:
References: