Vulnerability CVE-2011-0395


Published: 2011-02-25   Modified: 2012-02-13

Description:
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.20), 8.1 before 8.1(2.48), 8.2 before 8.2(3), and 8.3 before 8.3(2.1), when the RIP protocol and the Cisco Phone Proxy functionality are configured, allow remote attackers to cause a denial of service (device reload) via a RIP update, aka Bug ID CSCtg66583.

Type:

CWE-399

(Resource Management Errors)

Vendor: Cisco
Product: Adaptive security appliance software 
Version: 8.3(1); 8.0;
Product: Adaptive security appliance 
Version:
8.3
8.2(2)
8.2(1)
8.2
8.1(2)
8.1(1)
8.0(5)
8.0(4)
8.0(3)
8.0(2)
8.0
Product: Asa 5520 
Product: Pix firewall 506 
Product: Asa 5550 
Product: Asa 5500 
Product: Pix firewall 520 
Product: Pix 500 
Product: Asa 5510 
Product: Pix firewall 535 
Product: Pix 506e 
Product: Asa 5540 
Product: Pix firewall 515 
Product: Asa 5580 
Product: Asa 5505 
Product: Pix firewall 525 
Product: Pix 501 

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.8/10
6.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete

 References:
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14d.shtml
http://www.securitytracker.com/id?1025108
http://www.vupen.com/english/advisories/2011/0493
https://exchange.xforce.ibmcloud.com/vulnerabilities/65590

Related CVE
CVE-2019-16002
A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CS...
CVE-2019-15973
A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected application...
CVE-2019-15968
A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management...
CVE-2019-15994
A vulnerability in the web-based management interface of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected ...
CVE-2019-1982
A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass fi...
CVE-2019-1981
A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filteri...
CVE-2019-1980
A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filter...
CVE-2019-1978
A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filteri...

Copyright 2019, cxsecurity.com

 

Back to Top