First published: Thu Oct 23 2008(Updated: )
Memory leak in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 8.0 before 8.0(4) and 8.1 before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via an unspecified sequence of packets, related to the "initialization code for the hardware crypto accelerator."
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance 5500 | ||
Cisco PIX 506E | =8.0 | |
Cisco PIX 506E | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3817 has been classified as a high severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2008-3817, upgrade your Cisco Adaptive Security Appliance or PIX Security Appliance to versions 8.0(4) or 8.1(2) or later.
CVE-2008-3817 affects Cisco Adaptive Security Appliances 5500 Series and PIX Security Appliances running versions before 8.0(4) and 8.1(2).
The consequences of CVE-2008-3817 include potential denial of service due to remote attackers triggering memory leaks.
As a temporary workaround for CVE-2008-3817, you may implement traffic filtering to mitigate the impact of the vulnerability until a patch is applied.