Denial of Service Vulnerability in Cisco Adaptive Security Appliance
CVE-2016-9225
8.6HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 1 February 2017
Summary
A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module may allow an unauthenticated remote attacker to disrupt service by sending specially crafted fragmented IP traffic. This could exhaust system resources, leading to a denial of service condition where the CX module is unable to process further traffic. Notably, there are no patches or workarounds available to mitigate this vulnerability, putting all versions of this module at risk.
Affected Version(s)
all of the ASA CX Context-Aware Security module all versions of the ASA CX Context-Aware Security module
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved