Cisco ASA CX Context-Aware Security and Prime Security Manager Denial of Service Vulnerability
BID:55515
Info
Cisco ASA CX Context-Aware Security and Prime Security Manager Denial of Service Vulnerability
| Bugtraq ID: | 55515 |
| Class: | Design Error |
| CVE: |
CVE-2012-4629 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2012 12:00AM |
| Updated: | Mar 19 2015 08:41AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco ASA CX Context-Aware Security and Prime Security Manager Denial of Service Vulnerability
Cisco ASA CX Context-Aware Security and Prime Security Manager are prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the device to crash, denying service to legitimate users.
This issue is being tracked by the Cisco Bug ID CSCub70603.
The following versions are affected:
Versions prior to Cisco ASA CX Context-Aware Security 9.0.2-103
Versions prior to Cisco Prime Security Manager 9.0.2-103
Cisco ASA CX Context-Aware Security and Prime Security Manager are prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the device to crash, denying service to legitimate users.
This issue is being tracked by the Cisco Bug ID CSCub70603.
The following versions are affected:
Versions prior to Cisco ASA CX Context-Aware Security 9.0.2-103
Versions prior to Cisco Prime Security Manager 9.0.2-103
Exploit / POC
Cisco ASA CX Context-Aware Security and Prime Security Manager Denial of Service Vulnerability
To exploit this issue, attackers can use readily available network utilities.
To exploit this issue, attackers can use readily available network utilities.
Solution / Fix
Cisco ASA CX Context-Aware Security and Prime Security Manager Denial of Service Vulnerability
Solution:
The vendor has released updates. Please see the referenced advisory for details.
Solution:
The vendor has released updates. Please see the referenced advisory for details.
References
Cisco ASA CX Context-Aware Security and Prime Security Manager Denial of Service Vulnerability
References:
References: