CVE-2015-0742
The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105), 9.3(2.100), 9.4(0.115), 100.13(0.21), 100.13(20.3), 100.13(21.9), and 100.14(1.1) does not…
Does this matter?
Lower severity and a low EPSS score (2.97%). Track it; it rarely justifies an emergency change on its own.
Description
The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105), 9.3(2.100), 9.4(0.115), 100.13(0.21), 100.13(20.3), 100.13(21.9), and 100.14(1.1) does not properly implement multicast-forwarding registration, which allows remote attackers to cause a denial of service (forwarding outage) via a crafted multicast packet, aka Bug ID CSCus74398.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 2.97% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- cisco/adaptive security appliance software
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=38937Vendor Advisory
- http://www.securityfocus.com/bid/74750Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032381Third Party Advisory, VDB Entry
- http://tools.cisco.com/security/center/viewAlert.x?alertId=38937Vendor Advisory
- http://www.securityfocus.com/bid/74750Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032381Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.