Vulnslist

find the latest Cisco vulnerabilities

Vulnerability in Objective Systems ASN1C Compiler Affecting Cisco Products

cisco-sa-20160721-asn1c · Critical · Published · Updated

A vulnerability in the ASN1C compiler by Objective Systems affects Cisco ASR 5000 devices running StarOS and Cisco Virtualized Packet Core (VPC) systems. The vulnerability could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition or potentially execute arbitrary code. The vulnerability is due to unsafe code generation by the ASN1C compiler when creating ASN.1 translation functions that are subsequently included within affected Cisco products. An attacker could exploit this vulnerability by submitting a malicious Abstract Syntax Notation One (ASN.1) encoded message designed to trigger the issue to an affected function. US-CERT has released Vulnerability Note VU#790839 to document the issue. Cisco will release software updates that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160721-asn1c

Workarounds

No workarounds are available.

CVEsCVE-2016-5080
Cisco Bug IDsCSCva24310
CVSS ScoreBase 10.0
Base 10.0 AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:U/RC:C
Product Names From Source
Cisco ASR 5000 Series Software, Cisco Virtualized Packet Core

CSAF Product Statuses

Product Status Source CVE Rows
Cisco ASR 5000 Series Software known_affected cisco_csaf CVE-2016-5080 1
Cisco Virtualized Packet Core known_affected cisco_csaf CVE-2016-5080 1

Related Products

Product CVE Evidence
Cisco ASR 5000 Series Software CVE-2016-5080 Cisco OpenVuln · family-level
Cisco Virtualized Packet Core CVE-2016-5080 Cisco OpenVuln