First published: Thu Apr 18 2013(Updated: )
Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive Security Appliances (ASA) devices allows remote authenticated users to cause a denial of service (device reload) by accessing resources within multiple sessions, aka Bug ID CSCub58996.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco SSL VPN Appliances | ||
Cisco Adaptive Security Appliance Software | ||
Cisco Adaptive Security Appliance Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1199 has been rated as a medium severity vulnerability due to its potential to cause denial of service.
To fix CVE-2013-1199, update the Cisco Adaptive Security Appliance to the latest available software version recommended by Cisco.
CVE-2013-1199 affects remote authenticated users of Cisco Adaptive Security Appliances that utilize the Clientless SSL VPN component.
CVE-2013-1199 is a race condition vulnerability in the CIFS implementation of the Clientless SSL VPN on Cisco devices.
CVE-2013-1199 can be exploited by remote authenticated users accessing resources in multiple sessions, leading to device reload.