6.5
CVSSv3

CVE-2016-1385

Published: 26/05/2016 Updated: 15/08/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

The XML parser in Cisco Adaptive Security Appliance (ASA) Software up to and including 9.5.2 allows remote authenticated users to cause a denial of service (instability, memory consumption, or device reload) by leveraging (1) administrative access or (2) Clientless SSL VPN access to provide a crafted XML document, aka Bug ID CSCut14209.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco adaptive_security_appliance_software 8.4.0

cisco adaptive_security_appliance_software 8.4.1

cisco adaptive_security_appliance_software 8.4.1.3

cisco adaptive_security_appliance_software 8.4.1.11

cisco adaptive_security_appliance_software 8.4.2

cisco adaptive_security_appliance_software 8.4.2.1

cisco adaptive_security_appliance_software 8.4.2.8

cisco adaptive_security_appliance_software 8.4.3

cisco adaptive_security_appliance_software 8.4.3.8

cisco adaptive_security_appliance_software 8.4.3.9

cisco adaptive_security_appliance_software 8.4.4

cisco adaptive_security_appliance_software 8.4.4.1

cisco adaptive_security_appliance_software 8.4.4.3

cisco adaptive_security_appliance_software 8.4.4.5

cisco adaptive_security_appliance_software 8.4.4.9

cisco adaptive_security_appliance_software 8.4.5

cisco adaptive_security_appliance_software 8.4.5.6

cisco adaptive_security_appliance_software 8.4.6

cisco adaptive_security_appliance_software 8.4.7

cisco adaptive_security_appliance_software 8.4.7.3

cisco adaptive_security_appliance_software 8.4.7.15

cisco adaptive_security_appliance_software 8.4.7.22

cisco adaptive_security_appliance_software 8.4.7.23

cisco adaptive_security_appliance_software 8.4.7.26

cisco adaptive_security_appliance_software 8.4.7.28

cisco adaptive_security_appliance_software 8.4.7.29

cisco adaptive_security_appliance_software 8.5.1

cisco adaptive_security_appliance_software 8.5.1.1

cisco adaptive_security_appliance_software 8.5.1.6

cisco adaptive_security_appliance_software 8.5.1.7

cisco adaptive_security_appliance_software 8.5.1.14

cisco adaptive_security_appliance_software 8.5.1.17

cisco adaptive_security_appliance_software 8.5.1.18

cisco adaptive_security_appliance_software 8.5.1.19

cisco adaptive_security_appliance_software 8.5.1.21

cisco adaptive_security_appliance_software 8.5.1.24

cisco adaptive_security_appliance_software 8.6.1

cisco adaptive_security_appliance_software 8.6.1.1

cisco adaptive_security_appliance_software 8.6.1.2

cisco adaptive_security_appliance_software 8.6.1.5

cisco adaptive_security_appliance_software 8.6.1.10

cisco adaptive_security_appliance_software 8.6.1.12

cisco adaptive_security_appliance_software 8.6.1.13

cisco adaptive_security_appliance_software 8.6.1.14

cisco adaptive_security_appliance_software 8.6.1.17

cisco adaptive_security_appliance_software 8.7.1

cisco adaptive_security_appliance_software 8.7.1.1

cisco adaptive_security_appliance_software 8.7.1.3

cisco adaptive_security_appliance_software 8.7.1.4

cisco adaptive_security_appliance_software 8.7.1.7

cisco adaptive_security_appliance_software 8.7.1.8

cisco adaptive_security_appliance_software 8.7.1.11

cisco adaptive_security_appliance_software 8.7.1.13

cisco adaptive_security_appliance_software 8.7.1.16

cisco adaptive_security_appliance_software 8.7.1.17

cisco adaptive_security_appliance_software 9.0.1

cisco adaptive_security_appliance_software 9.0.2

cisco adaptive_security_appliance_software 9.0.2.10

cisco adaptive_security_appliance_software 9.0.3

cisco adaptive_security_appliance_software 9.0.3.6

cisco adaptive_security_appliance_software 9.0.3.8

cisco adaptive_security_appliance_software 9.0.4

cisco adaptive_security_appliance_software 9.0.4.1

cisco adaptive_security_appliance_software 9.0.4.5

cisco adaptive_security_appliance_software 9.0.4.7

cisco adaptive_security_appliance_software 9.0.4.17

cisco adaptive_security_appliance_software 9.0.4.20

cisco adaptive_security_appliance_software 9.0.4.24

cisco adaptive_security_appliance_software 9.0.4.26

cisco adaptive_security_appliance_software 9.0.4.29

cisco adaptive_security_appliance_software 9.0.4.33

cisco adaptive_security_appliance_software 9.0.4.35

cisco adaptive_security_appliance_software 9.0.4.37

cisco adaptive_security_appliance_software 9.1.1

cisco adaptive_security_appliance_software 9.1.1.4

cisco adaptive_security_appliance_software 9.1.2

cisco adaptive_security_appliance_software 9.1.2.8

cisco adaptive_security_appliance_software 9.1.3

cisco adaptive_security_appliance_software 9.1.3.2

cisco adaptive_security_appliance_software 9.1.4

cisco adaptive_security_appliance_software 9.1.4.5

cisco adaptive_security_appliance_software 9.1.5

cisco adaptive_security_appliance_software 9.1.5.10

cisco adaptive_security_appliance_software 9.1.5.12

cisco adaptive_security_appliance_software 9.1.5.15

cisco adaptive_security_appliance_software 9.1.5.21

cisco adaptive_security_appliance_software 9.1.6

cisco adaptive_security_appliance_software 9.1.6.1

cisco adaptive_security_appliance_software 9.1.6.4

cisco adaptive_security_appliance_software 9.1.6.6

cisco adaptive_security_appliance_software 9.1.6.8

cisco adaptive_security_appliance_software 9.1.6.10

cisco adaptive_security_appliance_software 9.2\\(0.0\\)

cisco adaptive_security_appliance_software 9.2\\(0.104\\)

cisco adaptive_security_appliance_software 9.2\\(3.1\\)

cisco adaptive_security_appliance_software 9.2.1

cisco adaptive_security_appliance_software 9.2.2

cisco adaptive_security_appliance_software 9.2.2.4

cisco adaptive_security_appliance_software 9.2.2.7

cisco adaptive_security_appliance_software 9.2.2.8

cisco adaptive_security_appliance_software 9.2.3

cisco adaptive_security_appliance_software 9.2.3.3

cisco adaptive_security_appliance_software 9.2.3.4

cisco adaptive_security_appliance_software 9.2.4

cisco adaptive_security_appliance_software 9.2.4.2

cisco adaptive_security_appliance_software 9.2.4.4

cisco adaptive_security_appliance_software 9.3\\(1.50\\)

cisco adaptive_security_appliance_software 9.3\\(1.105\\)

cisco adaptive_security_appliance_software 9.3\\(2.100\\)

cisco adaptive_security_appliance_software 9.3\\(2.243\\)

cisco adaptive_security_appliance_software 9.3.1

cisco adaptive_security_appliance_software 9.3.1.1

cisco adaptive_security_appliance_software 9.3.2

cisco adaptive_security_appliance_software 9.3.2.2

cisco adaptive_security_appliance_software 9.3.3

cisco adaptive_security_appliance_software 9.3.3.1

cisco adaptive_security_appliance_software 9.3.3.2

cisco adaptive_security_appliance_software 9.3.3.5

cisco adaptive_security_appliance_software 9.3.3.6

cisco adaptive_security_appliance_software 9.3.5

cisco adaptive_security_appliance_software 9.4.0.115

cisco adaptive_security_appliance_software 9.4.1

cisco adaptive_security_appliance_software 9.4.1.1

cisco adaptive_security_appliance_software 9.4.1.2

cisco adaptive_security_appliance_software 9.4.1.3

cisco adaptive_security_appliance_software 9.4.1.5

cisco adaptive_security_appliance_software 9.4.2

cisco adaptive_security_appliance_software 9.4.2.3

cisco adaptive_security_appliance_software 9.5.1

cisco adaptive_security_appliance_software 9.5.2

Recent Articles

Cisco patches security appliance bugs
The Register • Richard Chirgwin • 18 May 2016

ASA can be DoSsed by XML, VPN attacks

It's Borg Bug Day, and this week Cisco's issued patches of interest to users of its Adaptive Security Appliances (ASAs). The two newly-announced bugs are CVE-2016-1379, a VPN block memory exhaustion vulnerability; and CVE-2016-1385, a problem with the ASA XML parser. The memory exhaustion vulnerability affects ASA software releases later than 9.0, and can be exploited remotely. The software has a bug in how it handles ICMP errors in IPsec packets, and crafted packets sent either through LAN-to-L...