CVE-2013-5567
Cisco Adaptive Security Appliance (ASA) Software 8.4(.6) and earlier, when using an unsupported configuration with overlapping criteria for filtering and inspection, allows remote attackers to cause a denial of service (traffic loop and device crash)…
Does this matter?
Lower severity and a low EPSS score (2.12%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco Adaptive Security Appliance (ASA) Software 8.4(.6) and earlier, when using an unsupported configuration with overlapping criteria for filtering and inspection, allows remote attackers to cause a denial of service (traffic loop and device crash) via a packet that triggers multiple matches, aka Bug ID CSCui45606.
- CVSS 2.0
- 5.4 MEDIUMAV:N/AC:H/Au:N/C:N/I:N/A:C
- EPSS
- 2.12% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- cisco/adaptive security appliance software
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5567Broken Link, Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=34911Vendor Advisory
- http://www.securityfocus.com/bid/68504Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030555Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94445Third Party Advisory, VDB Entry
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5567Broken Link, Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=34911Vendor Advisory
- http://www.securityfocus.com/bid/68504Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030555Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94445Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.