First published: Wed May 02 2012(Updated: )
The ESMTP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.5 allows remote attackers to cause a denial of service (CPU consumption) via an unspecified closing sequence, aka Bug ID CSCtt32565.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software | =8.2\(1\) | |
Cisco Adaptive Security Appliance Software | =8.2\(2\) | |
Cisco Adaptive Security Appliance Software | =8.2\(3\) | |
Cisco Adaptive Security Appliance Software | =8.2\(3.9\) | |
Cisco Adaptive Security Appliance Software | =8.2\(4\) | |
Cisco Adaptive Security Appliance Software | =8.2\(4.1\) | |
Cisco Adaptive Security Appliance Software | =8.2\(4.4\) | |
Cisco Adaptive Security Appliance Software | =8.2\(5\) | |
Cisco Adaptive Security Appliance Software | =8.2.1 | |
Cisco Adaptive Security Appliance Software | =8.2.2 | |
Cisco Adaptive Security Appliance Software | =8.2.2-interim | |
Cisco Adaptive Security Appliance Software | =8.2.3 | |
Cisco Adaptive Security Appliance Software | =8.3\(1\) | |
Cisco Adaptive Security Appliance Software | =8.3\(2\) | |
Cisco Adaptive Security Appliance Software | =8.3.1 | |
Cisco Adaptive Security Appliance Software | =8.3.1-interim | |
Cisco Adaptive Security Appliance Software | =8.3.2 | |
Cisco Adaptive Security Appliance Software | =8.4 | |
Cisco Adaptive Security Appliance Software | =8.4\(1\) | |
Cisco Adaptive Security Appliance Software | =8.4\(1.11\) | |
Cisco Adaptive Security Appliance Software | =8.4\(2\) | |
Cisco Adaptive Security Appliance Software | =8.4\(2.11\) | |
Cisco Adaptive Security Appliance Software | =8.5 | |
Cisco Adaptive Security Appliance Software | =8.5\(1\) | |
Cisco Adaptive Security Appliance Software | =8.5\(1.4\) | |
Cisco Adaptive Security Appliance 5500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4006 has a severity rating that indicates it can cause a denial of service due to excessive CPU consumption.
To address CVE-2011-4006, upgrade your Cisco Adaptive Security Appliance software to a version that is not affected, such as versions above 8.5.
CVE-2011-4006 affects Cisco Adaptive Security Appliances 5500 series running software versions 8.2 through 8.5.
CVE-2011-4006 involves a denial of service attack that exploits a vulnerability in the ESMTP inspection feature.
If your Cisco device is impacted by CVE-2011-4006, you should implement the recommended patches or upgrade software versions immediately.