7.1
CVSSv2

CVE-2014-2129

Published: 10/04/2014 Updated: 15/08/2023
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 740
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

The SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software 8.2 prior to 8.2(5.48), 8.4 prior to 8.4(6.5), 9.0 prior to 9.0(3.1), and 9.1 prior to 9.1(2.5) allows remote malicious users to cause a denial of service (memory consumption or device reload) via crafted SIP packets, aka Bug ID CSCuh44052.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco adaptive security appliance software 8.2

cisco adaptive security appliance software 8.4

cisco adaptive security appliance software 9.0

cisco adaptive security appliance software 9.1

Vendor Advisories

Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities: Cisco ASA ASDM Privilege Escalation Vulnerability Cisco ASA SSL VPN Privilege Escalation Vulnerability Cisco ASA SSL VPN Authentication Bypass Vulnerability Cisco ASA SIP Denial of Service Vulnerability These vulnerabilities are indepen ...

Nmap Scripts

http-vuln-cve2014-2129

Detects whether the Cisco ASA appliance is vulnerable to the Cisco ASA SIP Denial of Service Vulnerability (CVE-2014-2129).

nmap -p 443 --script http-vuln-cve2014-2129 <target>

PORT STATE SERVICE 443/tcp open https | http-vuln-cve2014-2129: | VULNERABLE: | Cisco ASA SIP Denial of Service Vulnerability | State: VULNERABLE | Risk factor: High CVSSv2: 7.1 (HIGH) (AV:N/AC:M/AU:N/C:N/I:N/A:C) | Description: | The SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.48), 8.4 before 8.4(6.5), 9.0 before 9.0(3.1), and 9.1 before 9.1(2.5) allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted SIP packets, aka Bug ID CSCuh44052. | | References: | http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-asa |_ http://cvedetails.com/cve/2014-2129/
http-vuln-cve2014-2129

Detects whether the Cisco ASA appliance is vulnerable to the Cisco ASA SIP Denial of Service Vulnerability (CVE-2014-2129).

nmap -p 443 --script http-vuln-cve2014-2129 <target>

PORT STATE SERVICE 443/tcp open https | http-vuln-cve2014-2129: | VULNERABLE: | Cisco ASA SIP Denial of Service Vulnerability | State: VULNERABLE | Risk factor: High CVSSv2: 7.1 (HIGH) (AV:N/AC:M/AU:N/C:N/I:N/A:C) | Description: | The SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.48), 8.4 before 8.4(6.5), 9.0 before 9.0(3.1), and 9.1 before 9.1(2.5) allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted SIP packets, aka Bug ID CSCuh44052. | | References: | http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-asa |_ http://cvedetails.com/cve/2014-2129/