CVE-2012-6395: Input Validation
Cisco Adaptive Security Appliances (ASA) devices with firmware 8.4 do not properly validate unspecified input related to UNC share pathnames, which allows remote authenticated users to cause a denial of service (device crash) via unknown vectors, aka Bug ID CSCuc65775.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6395?
CVE-2012-6395 has a medium severity rating due to its potential to cause denial of service on affected Cisco ASA devices.
How do remote authenticated users exploit CVE-2012-6395?
Remote authenticated users can exploit CVE-2012-6395 by sending specifically crafted input related to UNC share pathnames to the affected Cisco devices.
What versions of Cisco ASA are affected by CVE-2012-6395?
CVE-2012-6395 affects Cisco Adaptive Security Appliances running firmware version 8.4.
What is the potential impact of CVE-2012-6395?
The potential impact of CVE-2012-6395 is a device crash, leading to a denial of service condition.
How can I mitigate the effects of CVE-2012-6395?
To mitigate CVE-2012-6395, it is recommended to update affected Cisco ASA devices to a fixed firmware version provided by Cisco.