Cisco ASA 9.3.2 OSPFv2 Handler Crash denial of service : 7/8/2015 3:07:59 PM

This eBook shows you how to build great push messages that convert for your app.
From our sponsors
 

 

Vulnerability Advisories
Vulnerabilities of scip VulDB

Cisco ASA 9.3.2 OSPFv2 Handler Crash denial of service
7/6/2015 7:00:00 PM

General

scipID: 76328
Affected: Cisco ASA 9.3.2
Published: 07/07/2015
Risk: problematic

Created: 07/08/2015
Entry: 71.9% complete

Summary

A vulnerability was found in Cisco ASA 9.3.2. It has been rated as problematic. Affected by this issue is an unknown function of the component OSPFv2 Handler. The manipulation with an unknown input leads to a denial of service vulnerability (crash). Impacted is availability.

The weakness was presented 07/07/2015 as 39641 as confirmed vulnerability alert (Website). The advisory is shared for download at tools.cisco.com. This vulnerability is handled as CVE-2015-4241 since 06/04/2015. The exploitation is known to be easy. The attack needs to approached within the local network. No form of authentication is required for exploitation. There are neither technical details nor an exploit publicly available.

The vulnerability is also documented in the vulnerability database at X-Force (104433).

CVSS

Base Score: 6.1 (CVSS2#AV:A/AC:L/Au:N/C:N/I:N/A:C) [?]
Temp Score: 4.5 (CVSS2#E:U/RL:OF/RC:C) [?]

CPE

Exploiting

Class: Denial of service
Local: No
Remote: Partially

Availability: No
Status: Unproven

Countermeasures

Recommended: no mitigation known
Status: Official fix
0-Day Time: 0 days since found

Timeline

06/04/2015 | CVE assigned
07/07/2015 | Advisory disclosed
07/08/2015 | VulDB entry created
07/08/2015 | VulDB entry updated

Sources

Advisory: 39641
Status: Confirmed

CVE: CVE-2015-4241 (mitre.org) (nvd.nist.org) (cvedetails.com)

X-Force: 104433 – Cisco Adaptive Security Appliance OSPFv2 denial of service

 

You are receiving this email because you subscribed to this feed at feedmyinbox.com

If you no longer wish to receive these emails, you can unsubscribe from this feed, or manage all your subscriptions

Diberdayakan oleh Blogger.