7.8
CVSSv2

CVE-2016-1312

Published: 09/03/2016 Updated: 03/12/2016
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The HTTPS inspection engine in the Content Security and Control Security Services Module (CSC-SSM) 6.6 prior to 6.6.1164.0 for Cisco ASA 5500 devices allows remote malicious users to cause a denial of service (memory consumption or device reload) via a flood of HTTPS packets, aka Bug ID CSCue76147.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco asa_5500_csc-ssm_firmware 6.6.1125.0

Vendor Advisories

A vulnerability in the HTTPS inspection engine of the Cisco ASA Content Security and Control Security Services Module (CSC-SSM) could allow an unauthenticated, remote attacker to cause exhaustion of available memory, system instability, and a reload of the affected system The vulnerability is due to improper handling of HTTPS packets transiting ...