Cisco ASA Appliance Crypto Accelerator Memory Leak Denial of Service Vulnerability
BID:31865
Info
Cisco ASA Appliance Crypto Accelerator Memory Leak Denial of Service Vulnerability
| Bugtraq ID: | 31865 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-3817 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2008 12:00AM |
| Updated: | Oct 22 2008 07:56PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Cisco PIX/ASA 8.1(1)5 Cisco PIX/ASA 8.1(1)4 Cisco PIX/ASA 8.1(1)2 Cisco PIX/ASA 8.1(1)1 Cisco PIX/ASA 8.1 Cisco PIX/ASA 8.0(3)9 Cisco PIX/ASA 8.0(3)15 Cisco PIX/ASA 8.0(3)14 Cisco PIX/ASA 8.0(3)10 Cisco PIX/ASA 8.0(3) Cisco PIX/ASA 8.0(2)17 Cisco PIX/ASA 8.0(2) Cisco PIX/ASA 8.0 Cisco PIX/ASA 8.0 |
| Not Vulnerable: |
Cisco PIX/ASA 8.1(2) Cisco PIX/ASA 8.0(4) |
Discussion
Cisco ASA Appliance Crypto Accelerator Memory Leak Denial of Service Vulnerability
Cisco ASA security appliances are prone to a remote denial-of-service vulnerability.
The hardware Crypto Accelerator included with these appliances is prone to a denial-of-service vulnerability. Specifically, the initialization code for the vulnerable hardware will leak memory when processing a specific sequence of packets.
An attacker can exploit this issue by sending specially crafted packets to cause the affected devices to reload, denying service to legitimate users. Repeat attacks will result in a prolonged denial-of-service condition. This issue is documented in Cisco Bug ID CSCsj25896.
Cisco ASA security appliances are prone to a remote denial-of-service vulnerability.
The hardware Crypto Accelerator included with these appliances is prone to a denial-of-service vulnerability. Specifically, the initialization code for the vulnerable hardware will leak memory when processing a specific sequence of packets.
An attacker can exploit this issue by sending specially crafted packets to cause the affected devices to reload, denying service to legitimate users. Repeat attacks will result in a prolonged denial-of-service condition. This issue is documented in Cisco Bug ID CSCsj25896.
Exploit / POC
Cisco ASA Appliance Crypto Accelerator Memory Leak Denial of Service Vulnerability
To exploit this issue, attackers can use readily available network utilities.
To exploit this issue, attackers can use readily available network utilities.
Solution / Fix
Cisco ASA Appliance Crypto Accelerator Memory Leak Denial of Service Vulnerability
Solution:
The vendor has released updates. Please see the referenced advisory for more information.
Solution:
The vendor has released updates. Please see the referenced advisory for more information.
References
Cisco ASA Appliance Crypto Accelerator Memory Leak Denial of Service Vulnerability
References:
References:
- Cisco Homepage (Cisco )
- Cisco Security Advisory: Multiple Vulnerabilities in Cisco PIX and Cisco ASA (Cisco Systems Product Security Incident Response Team
) - cisco-sa-20081022-asa Cisco Security Advisory: Multiple Vulnerabilities in Cisco (Cisco)