CVE-2012-0353: Input Validation
The UDP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.5), 8.3 before 8.3(2.22), 8.4 before 8.4(2.1), and 8.5 before 8.5(1.2) does not properly handle flows, which allows remote attackers to cause a denial of service (device reload) via a crafted series of (1) IPv4 or (2) IPv6 UDP packets, aka Bug ID CSCtq10441.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0353?
CVE-2012-0353 is classified as a medium severity vulnerability affecting specific Cisco Adaptive Security Appliance (ASA) devices.
How do I fix CVE-2012-0353?
To fix CVE-2012-0353, ensure that your Cisco ASA device is updated to a software version that is 8.0(5.25) or later.
Which devices are affected by CVE-2012-0353?
CVE-2012-0353 affects Cisco Adaptive Security Appliances, specifically the 5500 series, and the ASA Services Module in Cisco Catalyst 6500 series devices.
What types of vulnerabilities are related to CVE-2012-0353?
CVE-2012-0353 is related to vulnerabilities in the UDP inspection engine of Cisco ASA devices, which can lead to potential denial of service.
What versions of Cisco ASA software are vulnerable to CVE-2012-0353?
Cisco ASA software versions prior to 8.0(5.25), 8.1(2.50), 8.2(5.5), 8.3(2.22), 8.4(2.1), and 8.5 are vulnerable to CVE-2012-0353.