Denial of Service Vulnerability in Cisco ASA 5500 Devices
CVE-2016-1312
7.5HIGH
What is CVE-2016-1312?
The HTTPS inspection engine in Cisco's Content Security and Control Security Services Module (CSC-SSM) prior to version 6.6.1164.0 for ASA 5500 devices is vulnerable to a denial of service attack. Remote attackers can exploit this flaw by flooding the device with multiple HTTPS packets, which can lead to excessive memory consumption or even cause the device to reload, disrupting normal operations and affecting overall network security.