First published: Fri Jan 18 2013(Updated: )
Cisco Adaptive Security Appliances (ASA) devices with firmware 8.4 do not properly validate unspecified input related to UNC share pathnames, which allows remote authenticated users to cause a denial of service (device crash) via unknown vectors, aka Bug ID CSCuc65775.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software | =8.4 | |
Cisco Adaptive Security Appliance Software | ||
Cisco ASA 1000V Cloud Firewall | ||
Cisco ASA 5500 CSC-SSM |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-6395 has a medium severity rating due to its potential to cause denial of service on affected Cisco ASA devices.
Remote authenticated users can exploit CVE-2012-6395 by sending specifically crafted input related to UNC share pathnames to the affected Cisco devices.
CVE-2012-6395 affects Cisco Adaptive Security Appliances running firmware version 8.4.
The potential impact of CVE-2012-6395 is a device crash, leading to a denial of service condition.
To mitigate CVE-2012-6395, it is recommended to update affected Cisco ASA devices to a fixed firmware version provided by Cisco.