First published: Thu Sep 04 2008(Updated: )
Memory leak in the crypto functionality in Cisco Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a clientless SSL VPN endpoint, allows remote attackers to cause a denial of service (memory consumption and VPN hang) via a crafted SSL or HTTP packet, aka Bug ID CSCso66472.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance 5500 | =8.1 | |
Cisco Adaptive Security Appliance 5500 | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-2734 is considered high due to its potential to cause denial of service affects in affected devices.
To fix CVE-2008-2734, upgrade your Cisco Adaptive Security Appliance 5500 devices to the latest firmware version recommended by Cisco.
CVE-2008-2734 affects Cisco Adaptive Security Appliance 5500 devices running versions 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4.
CVE-2008-2734 allows remote attackers to exploit the memory leak to cause denial of service by consuming memory resources.
You can determine if your device is vulnerable to CVE-2008-2734 by checking its version against the affected versions listed in the advisory.