Cisco ASA UDP Inspection Engine Denial of Service Vulnerability
BID:52484
Info
Cisco ASA UDP Inspection Engine Denial of Service Vulnerability
| Bugtraq ID: | 52484 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2012-0353 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2012 12:00AM |
| Updated: | Mar 19 2015 08:45AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Catalyst 6500 Series ASA Services Module 8.5 Cisco Catalyst 6500 Series ASA Services Module 8.4 Cisco Catalyst 6500 Series ASA Services Module 8.3 Cisco Catalyst 6500 Series ASA Services Module 8.2 Cisco Catalyst 6500 Series ASA Services Module 8.1 Cisco Catalyst 6500 Series ASA Services Module 8.0 Cisco ASA 5500 Series Adaptive Security Appliance 8.5(1.1) Cisco ASA 5500 Series Adaptive Security Appliance 8.5 Cisco ASA 5500 Series Adaptive Security Appliance 8.4(2) Cisco ASA 5500 Series Adaptive Security Appliance 8.4(1.10) Cisco ASA 5500 Series Adaptive Security Appliance 8.4(1) Cisco ASA 5500 Series Adaptive Security Appliance 8.4 Cisco ASA 5500 Series Adaptive Security Appliance 8.3(2.20) Cisco ASA 5500 Series Adaptive Security Appliance 8.3(2.18) Cisco ASA 5500 Series Adaptive Security Appliance 8.3(2.13) Cisco ASA 5500 Series Adaptive Security Appliance 8.3(2) Cisco ASA 5500 Series Adaptive Security Appliance 8.3(1.8) Cisco ASA 5500 Series Adaptive Security Appliance 8.3(1.6) Cisco ASA 5500 Series Adaptive Security Appliance 8.3(1.1) Cisco ASA 5500 Series Adaptive Security Appliance 8.3(0.08) Cisco ASA 5500 Series Adaptive Security Appliance 8.3 Cisco ASA 5500 Series Adaptive Security Appliance 8.2(5.3) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(5) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(4.1) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(4) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(3) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(2.19) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(2.17) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(2.13) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(2.10) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(2.1) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(2) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(1.5) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(1.2) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(1.16) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(1.15) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(1.10) Cisco ASA 5500 Series Adaptive Security Appliance 8.2 Cisco ASA 5500 Series Adaptive Security Appliance 8.1 Cisco ASA 5500 Series Adaptive Security Appliance 8.0(5.7) Cisco ASA 5500 Series Adaptive Security Appliance 8.0(5.6) Cisco ASA 5500 Series Adaptive Security Appliance 8.0(5.24) Cisco ASA 5500 Series Adaptive Security Appliance 8.0(5.23) Cisco ASA 5500 Series Adaptive Security Appliance 8.0(5.2) Cisco ASA 5500 Series Adaptive Security Appliance 8.0(5.19) Cisco ASA 5500 Series Adaptive Security Appliance 8.0(5.17) Cisco ASA 5500 Series Adaptive Security Appliance 8.0(5.15) Cisco ASA 5500 Series Adaptive Security Appliance 8.0(5.1) Cisco ASA 5500 Series Adaptive Security Appliance 8.0(4.44) Cisco ASA 5500 Series Adaptive Security Appliance 8.0(4.38) Cisco ASA 5500 Series Adaptive Security Appliance 8.0 |
| Not Vulnerable: |
Cisco Catalyst 6500 Series ASA Services Module 8.5(1.2) Cisco Catalyst 6500 Series ASA Services Module 8.4(2.1) Cisco Catalyst 6500 Series ASA Services Module 8.3(2.22) Cisco Catalyst 6500 Series ASA Services Module 8.2(5.5) Cisco Catalyst 6500 Series ASA Services Module 8.1(2.50) Cisco Catalyst 6500 Series ASA Services Module 8.0(5.25) Cisco ASA 5500 Series Adaptive Security Appliance 8.5(1.2) Cisco ASA 5500 Series Adaptive Security Appliance 8.4(2.1) Cisco ASA 5500 Series Adaptive Security Appliance 8.3(2.22) Cisco ASA 5500 Series Adaptive Security Appliance 8.2(5.5) Cisco ASA 5500 Series Adaptive Security Appliance 8.1(2.50) Cisco ASA 5500 Series Adaptive Security Appliance 8.0(5.25) |
Discussion
Cisco ASA UDP Inspection Engine Denial of Service Vulnerability
Cisco ASA UDP Inspection Engine is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an affected device to reload, denying service to legitimate users.
The following Cisco products are vulnerable:
Cisco ASA 5500 Series Adaptive Security Appliances.
Cisco Catalyst 6500 Series ASA Services Module.
This issue is being tracked by Cisco Bug ID CSCtq10441.
Cisco ASA UDP Inspection Engine is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an affected device to reload, denying service to legitimate users.
The following Cisco products are vulnerable:
Cisco ASA 5500 Series Adaptive Security Appliances.
Cisco Catalyst 6500 Series ASA Services Module.
This issue is being tracked by Cisco Bug ID CSCtq10441.
Exploit / POC
Cisco ASA UDP Inspection Engine Denial of Service Vulnerability
To exploit this issue, attackers can use readily available network utilities.
To exploit this issue, attackers can use readily available network utilities.
Solution / Fix
Cisco ASA UDP Inspection Engine Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Cisco ASA UDP Inspection Engine Denial of Service Vulnerability
References:
References: