CVE-2011-4006: Input Validation
The ESMTP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.5 allows remote attackers to cause a denial of service (CPU consumption) via an unspecified closing sequence, aka Bug ID CSCtt32565.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4006?
CVE-2011-4006 has a severity rating that indicates it can cause a denial of service due to excessive CPU consumption.
How do I fix CVE-2011-4006?
To address CVE-2011-4006, upgrade your Cisco Adaptive Security Appliance software to a version that is not affected, such as versions above 8.5.
Which devices are affected by CVE-2011-4006?
CVE-2011-4006 affects Cisco Adaptive Security Appliances 5500 series running software versions 8.2 through 8.5.
What type of attack does CVE-2011-4006 involve?
CVE-2011-4006 involves a denial of service attack that exploits a vulnerability in the ESMTP inspection feature.
What should I do if my Cisco device is impacted by CVE-2011-4006?
If your Cisco device is impacted by CVE-2011-4006, you should implement the recommended patches or upgrade software versions immediately.