Denial of Service Vulnerability in Cisco Adaptive Security Appliance
CVE-2016-9225

8.6HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
1 February 2017

Summary

A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module may allow an unauthenticated remote attacker to disrupt service by sending specially crafted fragmented IP traffic. This could exhaust system resources, leading to a denial of service condition where the CX module is unable to process further traffic. Notably, there are no patches or workarounds available to mitigate this vulnerability, putting all versions of this module at risk.

Affected Version(s)

all of the ASA CX Context-Aware Security module all versions of the ASA CX Context-Aware Security module

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.