SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-3788

Race condition in Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), and 7.0(4), when running with an Active/Standby configuration and when the failover LAN interface fails, allows remote attackers to cause a denial of service (standby firewall…

MEDIUM 5.4EPSS 2.65%

Does this matter?

Lower severity and a low EPSS score (2.65%). Track it; it rarely justifies an emergency change on its own.

Description

Race condition in Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), and 7.0(4), when running with an Active/Standby configuration and when the failover LAN interface fails, allows remote attackers to cause a denial of service (standby firewall failure) by sending spoofed ARP responses from an IP address of an active firewall, which prevents the standby firewall from becoming active, aka "failover denial of service."

CVSS 2.0
5.4 MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
EPSS
2.65% probability · 85th percentile
CISA KEV
Not listed
Affected
cisco/adaptive security appliance software
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.