Cisco ASA CIFS Share Enumeration Denial of Service Vulnerability

Related Vulnerabilities: CVE-2013-6691  

A vulnerability in the WebVPN Common Internet File System (CIFS) access function of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, remote attacker to trigger a reload of the affected device. The vulnerability is due to missing bounds checks on the response received from the CIFS server when enumerating available shares. An attacker could exploit this vulnerability by attempting to attain the list of shares from CIFS servers that offer a large number of shares. Controlling a CIFS server may also aid the attacker. An exploit could allow the attacker to trigger a reload of the Cisco ASA, resulting in a denial of service (DoS) condition. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker must authenticate to a targeted device. This access requirement may reduce the possibility of a successful exploit.