6.8
CVSSv2

CVE-2016-1379

Published: 28/05/2016 Updated: 15/08/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

Cisco Adaptive Security Appliance (ASA) Software 9.0 up to and including 9.5.1 mishandles IPsec error processing, which allows remote authenticated users to cause a denial of service (memory consumption) via crafted (1) LAN-to-LAN or (2) Remote Access VPN tunnel packets, aka Bug ID CSCuv70576.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco adaptive security appliance software 9.3.2

cisco adaptive security appliance software 9.1.1.4

cisco adaptive security appliance software 9.1.4

cisco adaptive security appliance software 9.2.2.7

cisco adaptive security appliance software 9.1.5.21

cisco adaptive security appliance software 9.1.3

cisco adaptive security appliance software 9.1.2

cisco adaptive security appliance software 9.2.3

cisco adaptive security appliance software 9.3.1.1

cisco adaptive security appliance software 9.1.1

cisco adaptive security appliance software 9.2.2.8

cisco adaptive security appliance software 9.3.1

cisco adaptive security appliance software 9.1.2.8

cisco adaptive security appliance software 9.1.5.15

cisco adaptive security appliance software 9.1.5.10

cisco adaptive security appliance software 9.2.1

cisco adaptive security appliance software 9.3.2.2

cisco adaptive security appliance software 9.1.5

cisco adaptive security appliance software 9.2.2.4

cisco adaptive security appliance software 9.1.5.12

cisco adaptive security appliance software 9.1.3.2

cisco adaptive security appliance software 9.1.4.5

cisco adaptive security appliance software 9.2.2

cisco adaptive security appliance software 9.3.3.2

cisco adaptive security appliance software 9.1.6.6

cisco adaptive security appliance software 9.1.6.1

cisco adaptive security appliance software 9.2\\(3.1\\)

cisco adaptive security appliance software 9.3\\(2.100\\)

cisco adaptive security appliance software 9.2\\(0.104\\)

cisco adaptive security appliance software 9.4.1.2

cisco adaptive security appliance software 9.2\\(0.0\\)

cisco adaptive security appliance software 9.3\\(1.105\\)

cisco adaptive security appliance software 9.1.6

cisco adaptive security appliance software 9.3.3

cisco adaptive security appliance software 9.3.3.5

cisco adaptive security appliance software 9.2.4

cisco adaptive security appliance software 9.1.6.4

cisco adaptive security appliance software 9.2.3.3

cisco adaptive security appliance software 9.5.1

cisco adaptive security appliance software 9.2.3.4

cisco adaptive security appliance software 9.3.3.1

cisco adaptive security appliance software 9.4.1.5

cisco adaptive security appliance software 9.4.1.3

cisco adaptive security appliance software 9.4.1

cisco adaptive security appliance software 9.1.6.8

cisco adaptive security appliance software 9.3\\(2.243\\)

cisco adaptive security appliance software 9.3\\(1.50\\)

cisco adaptive security appliance software 9.4.0.115

cisco adaptive security appliance software 9.4.1.1

cisco adaptive security appliance software 9.3.3.6

cisco adaptive security appliance software 9.0.4.37

cisco adaptive security appliance software 9.0.4

cisco adaptive security appliance software 9.0.4.5

cisco adaptive security appliance software 9.0.4.7

cisco adaptive security appliance software 9.0.4.26

cisco adaptive security appliance software 9.0.3.8

cisco adaptive security appliance software 9.0.4.35

cisco adaptive security appliance software 9.0.4.17

cisco adaptive security appliance software 9.0.3.6

cisco adaptive security appliance software 9.0.2.10

cisco adaptive security appliance software 9.0.1

cisco adaptive security appliance software 9.0.4.33

cisco adaptive security appliance software 9.0.4.24

cisco adaptive security appliance software 9.0.2

cisco adaptive security appliance software 9.0.4.20

cisco adaptive security appliance software 9.0.4.29

cisco adaptive security appliance software 9.0.3

cisco adaptive security appliance software 9.0.4.1

Recent Articles

Cisco patches security appliance bugs
The Register • Richard Chirgwin • 18 May 2016

ASA can be DoSsed by XML, VPN attacks

It's Borg Bug Day, and this week Cisco's issued patches of interest to users of its Adaptive Security Appliances (ASAs). The two newly-announced bugs are CVE-2016-1379, a VPN block memory exhaustion vulnerability; and CVE-2016-1385, a problem with the ASA XML parser. The memory exhaustion vulnerability affects ASA software releases later than 9.0, and can be exploited remotely. The software has a bug in how it handles ICMP errors in IPsec packets, and crafted packets sent either through LAN-to-L...