First published: Thu Apr 11 2013(Updated: )
Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.28), 8.1 and 8.2 before 8.2(5.35), 8.3 before 8.3(2.34), 8.4 before 8.4(4.11), 8.6 before 8.6(1.10), and 8.7 before 8.7(1.3), and Cisco Firewall Services Module (FWSM) software 3.1 and 3.2 before 3.2(24.1) and 4.0 and 4.1 before 4.1(11.1), allow remote attackers to cause a denial of service (device reload) via a crafted IKEv1 message, aka Bug IDs CSCub85692 and CSCud20267.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software | =7.0 | |
Cisco Adaptive Security Appliance Software | =7.0\(0\) | |
Cisco Adaptive Security Appliance Software | =7.0\(1\) | |
Cisco Adaptive Security Appliance Software | =7.0\(2\) | |
Cisco Adaptive Security Appliance Software | =7.0\(4\) | |
Cisco Adaptive Security Appliance Software | =7.0\(5\) | |
Cisco Adaptive Security Appliance Software | =7.0\(5.2\) | |
Cisco Adaptive Security Appliance Software | =7.0\(6\) | |
Cisco Adaptive Security Appliance Software | =7.0\(6.7\) | |
Cisco Adaptive Security Appliance Software | =7.0\(7\) | |
Cisco Adaptive Security Appliance Software | =7.0\(8\) | |
Cisco Adaptive Security Appliance Software | =7.0.1 | |
Cisco Adaptive Security Appliance Software | =7.0.1.4 | |
Cisco Adaptive Security Appliance Software | =7.0.2 | |
Cisco Adaptive Security Appliance Software | =7.0.4 | |
Cisco Adaptive Security Appliance Software | =7.0.4.3 | |
Cisco Adaptive Security Appliance Software | =7.0.5 | |
Cisco Adaptive Security Appliance Software | =7.0.6 | |
Cisco Adaptive Security Appliance Software | =7.0.7 | |
Cisco Adaptive Security Appliance Software | =7.0.8 | |
Cisco Adaptive Security Appliance Software | =7.0.8-interim | |
Cisco Adaptive Security Appliance Software | =7.1 | |
Cisco Adaptive Security Appliance Software | =7.1\(2\) | |
Cisco Adaptive Security Appliance Software | =7.1\(2.5\) | |
Cisco Adaptive Security Appliance Software | =7.1\(2.27\) | |
Cisco Adaptive Security Appliance Software | =7.1\(2.48\) | |
Cisco Adaptive Security Appliance Software | =7.1\(2.49\) | |
Cisco Adaptive Security Appliance Software | =7.1\(5\) | |
Cisco Adaptive Security Appliance Software | =7.1.1 | |
Cisco Adaptive Security Appliance Software | =7.1.2 | |
Cisco Adaptive Security Appliance Software | =7.2 | |
Cisco Adaptive Security Appliance Software | =7.2\(1\) | |
Cisco Adaptive Security Appliance Software | =7.2\(1.22\) | |
Cisco Adaptive Security Appliance Software | =7.2\(2\) | |
Cisco Adaptive Security Appliance Software | =7.2\(2.5\) | |
Cisco Adaptive Security Appliance Software | =7.2\(2.7\) | |
Cisco Adaptive Security Appliance Software | =7.2\(2.8\) | |
Cisco Adaptive Security Appliance Software | =7.2\(2.10\) | |
Cisco Adaptive Security Appliance Software | =7.2\(2.14\) | |
Cisco Adaptive Security Appliance Software | =7.2\(2.15\) | |
Cisco Adaptive Security Appliance Software | =7.2\(2.16\) | |
Cisco Adaptive Security Appliance Software | =7.2\(2.17\) | |
Cisco Adaptive Security Appliance Software | =7.2\(2.18\) | |
Cisco Adaptive Security Appliance Software | =7.2\(2.19\) | |
Cisco Adaptive Security Appliance Software | =7.2\(2.48\) | |
Cisco Adaptive Security Appliance Software | =7.2\(3\) | |
Cisco Adaptive Security Appliance Software | =7.2\(4\) | |
Cisco Adaptive Security Appliance Software | =7.2\(5\) | |
Cisco Adaptive Security Appliance Software | =7.2.1 | |
Cisco Adaptive Security Appliance Software | =7.2.2 | |
Cisco Adaptive Security Appliance Software | =7.2.3 | |
Cisco Adaptive Security Appliance Software | =7.2.4 | |
Cisco Adaptive Security Appliance Software | =7.2.5 | |
Cisco Adaptive Security Appliance 5500 | ||
Cisco 6500 series Adaptive Security Appliance | ||
Cisco 7600 series Adaptive Security Appliance | ||
Cisco Adaptive Security Appliance Software | =8.0\(2\) | |
Cisco Adaptive Security Appliance Software | =8.0\(3\) | |
Cisco Adaptive Security Appliance Software | =8.0\(4\) | |
Cisco Adaptive Security Appliance Software | =8.0\(5\) | |
Cisco Adaptive Security Appliance Software | =8.0.2 | |
Cisco Adaptive Security Appliance Software | =8.0.3 | |
Cisco Adaptive Security Appliance Software | =8.0.4 | |
Cisco Adaptive Security Appliance Software | =8.0.5 | |
Cisco Adaptive Security Appliance Software | =8.1 | |
Cisco Adaptive Security Appliance Software | =8.2 | |
Cisco Adaptive Security Appliance Software | =8.2\(1\) | |
Cisco Adaptive Security Appliance Software | =8.2\(2\) | |
Cisco Adaptive Security Appliance Software | =8.2\(3\) | |
Cisco Adaptive Security Appliance Software | =8.2\(3.9\) | |
Cisco Adaptive Security Appliance Software | =8.2\(4\) | |
Cisco Adaptive Security Appliance Software | =8.2\(4.1\) | |
Cisco Adaptive Security Appliance Software | =8.2\(4.4\) | |
Cisco Adaptive Security Appliance Software | =8.2\(5\) | |
Cisco Adaptive Security Appliance Software | =8.2\(5.35\) | |
Cisco Adaptive Security Appliance Software | =8.2\(5.38\) | |
Cisco Adaptive Security Appliance Software | =8.2.1 | |
Cisco Adaptive Security Appliance Software | =8.2.2 | |
Cisco Adaptive Security Appliance Software | =8.2.2-interim | |
Cisco Adaptive Security Appliance Software | =8.2.3 | |
Cisco Adaptive Security Appliance Software | =8.3\(1\) | |
Cisco Adaptive Security Appliance Software | =8.3\(2\) | |
Cisco Adaptive Security Appliance Software | =8.3.1 | |
Cisco Adaptive Security Appliance Software | =8.3.1-interim | |
Cisco Adaptive Security Appliance Software | =8.3.2 | |
Cisco Adaptive Security Appliance Software | =8.4 | |
Cisco Adaptive Security Appliance Software | =8.4\(1\) | |
Cisco Adaptive Security Appliance Software | =8.4\(1.11\) | |
Cisco Adaptive Security Appliance Software | =8.4\(2\) | |
Cisco Adaptive Security Appliance Software | =8.4\(2.11\) | |
Cisco Adaptive Security Appliance Software | =8.6 | |
Cisco Adaptive Security Appliance Software | =8.6\(1\) | |
Cisco Adaptive Security Appliance Software | =8.7.1 | |
Cisco Adaptive Security Appliance Software | =8.7.1.1 | |
Cisco Firewall Services Module | =3.1 | |
Cisco Firewall Services Module | =3.2 | |
Cisco Firewall Services Module | =3.2\(1\) | |
Cisco Firewall Services Module | =3.2\(2\) | |
Cisco Firewall Services Module | =3.2\(3\) | |
Cisco Firewall Services Module | =3.2\(4\) | |
Cisco Firewall Services Module | =3.2\(5\) | |
Cisco Firewall Services Module | =3.2\(6\) | |
Cisco Firewall Services Module | =3.2\(7\) | |
Cisco Firewall Services Module | =3.2\(8\) | |
Cisco Firewall Services Module | =3.2\(9\) | |
Cisco Firewall Services Module | =3.2\(10\) | |
Cisco Firewall Services Module | =3.2\(11\) | |
Cisco Firewall Services Module | =3.2\(12\) | |
Cisco Firewall Services Module | =3.2\(13\) | |
Cisco Firewall Services Module | =3.2\(14\) | |
Cisco Firewall Services Module | =3.2\(15\) | |
Cisco Firewall Services Module | =3.2\(16\) | |
Cisco Firewall Services Module | =3.2\(17\) | |
Cisco Firewall Services Module | =3.2\(18\) | |
Cisco Firewall Services Module | =3.2\(19\) | |
Cisco Firewall Services Module | =3.2\(20\) | |
Cisco Firewall Services Module | =3.2\(21\) | |
Cisco Firewall Services Module | =3.2\(22\) | |
Cisco Firewall Services Module | =3.2\(24\) | |
Cisco Firewall Services Module | =4.0 | |
Cisco Firewall Services Module | =4.1 | |
Cisco Firewall Services Module | =4.1\(1\) | |
Cisco Firewall Services Module | =4.1\(2\) | |
Cisco Firewall Services Module | =4.1\(3\) | |
Cisco Firewall Services Module | =4.1\(4\) | |
Cisco Firewall Services Module | =4.1\(5\) | |
Cisco Firewall Services Module | =4.1\(6\) | |
Cisco Firewall Services Module | =4.1\(7\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1149 has a critical severity rating due to potential remote code execution vulnerabilities in affected Cisco ASA and FWSM software.
To fix CVE-2013-1149, upgrade to the patched versions of Cisco ASA software or Firewall Services Module software as specified in Cisco's security advisory.
CVE-2013-1149 affects Cisco Adaptive Security Appliances (ASA) and Firewall Services Module (FWSM) devices running specific vulnerable software versions.
There have been indications that CVE-2013-1149 may be actively exploited in the wild, which heightens the urgency for remediation.
Implementing network segmentation and restricting access to management interfaces are recommended practices to mitigate potential risks from CVE-2013-1149.