Vulnslist

find the latest Cisco vulnerabilities

Cisco ASA Content Security and Control Security Services Module Denial of Service Vulnerability

cisco-sa-20160309-csc · High · Published · Updated

A vulnerability in the HTTPS inspection engine of the Cisco ASA Content Security and Control Security Services Module (CSC-SSM) could allow an unauthenticated, remote attacker to cause exhaustion of available memory, system instability, and a reload of the affected system. The vulnerability is due to improper handling of HTTPS packets transiting through the affected system. An attacker could exploit this vulnerability by sending HTTPS packets through the affected system at high rate.  Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160309-csc

Workarounds

Workarounds are not available.

CVEsCVE-2016-1312
Cisco Bug IDsCSCue76147
CVSS ScoreBase 7.8
Base 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C
Product Names From Source
Cisco ASA 5500 Series CSC-SSM

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2016-1312 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2016-1312 Cisco OpenVuln
Cisco Adaptive Security Appliance (ASA) Software CVE-2016-1312 Cisco OpenVuln
Cisco ASA 5500 Series CSC-SSM CVE-2016-1312 Cisco OpenVuln