First published: Sun Oct 13 2013(Updated: )
The Clientless SSL VPN feature in Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.44), 8.3.x before 8.3(2.39), 8.4.x before 8.4(5.7), 8.6.x before 8.6(1.12), 9.0.x before 9.0(2.6), and 9.1.x before 9.1(1.7) allows remote attackers to cause a denial of service (device reload) via crafted HTTPS requests, aka Bug ID CSCua22709.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance | =8.0 | |
Cisco Adaptive Security Appliance | =8.0\(2\) | |
Cisco Adaptive Security Appliance | =8.0\(3\) | |
Cisco Adaptive Security Appliance | =8.0\(4\) | |
Cisco Adaptive Security Appliance | =8.0\(5\) | |
Cisco Adaptive Security Appliance | =8.0\(5.28\) | |
Cisco Adaptive Security Appliance | =8.0\(5.31\) | |
Cisco Adaptive Security Appliance | =8.0.2 | |
Cisco Adaptive Security Appliance Software | =8.0.3 | |
Cisco Adaptive Security Appliance Software | =8.0.4 | |
Cisco Adaptive Security Appliance Software | =8.0.5 | |
Cisco Adaptive Security Appliance Software | =8.1 | |
Cisco Adaptive Security Appliance Software | =8.2 | |
Cisco Adaptive Security Appliance Software | =8.2\(1\) | |
Cisco Adaptive Security Appliance Software | =8.2\(2\) | |
Cisco Adaptive Security Appliance Software | =8.2\(3\) | |
Cisco Adaptive Security Appliance Software | =8.2\(3.9\) | |
Cisco Adaptive Security Appliance Software | =8.2\(4\) | |
Cisco Adaptive Security Appliance Software | =8.2\(4.1\) | |
Cisco Adaptive Security Appliance Software | =8.2\(4.4\) | |
Cisco Adaptive Security Appliance Software | =8.2\(5\) | |
Cisco Adaptive Security Appliance Software | =8.2\(5.35\) | |
Cisco Adaptive Security Appliance Software | =8.2\(5.38\) | |
Cisco Adaptive Security Appliance Software | =8.3\(1\) | |
Cisco Adaptive Security Appliance Software | =8.3\(2\) | |
Cisco Adaptive Security Appliance Software | =8.3\(2.34\) | |
Cisco Adaptive Security Appliance Software | =8.3\(2.37\) | |
Cisco Adaptive Security Appliance Software | =8.4 | |
Cisco Adaptive Security Appliance Software | =8.4\(1\) | |
Cisco Adaptive Security Appliance Software | =8.4\(1.11\) | |
Cisco Adaptive Security Appliance Software | =8.4\(2\) | |
Cisco Adaptive Security Appliance Software | =8.4\(2.11\) | |
Cisco Adaptive Security Appliance Software | =8.4\(3\) | |
Cisco Adaptive Security Appliance Software | =8.4\(4.11\) | |
Cisco Adaptive Security Appliance Software | =8.4\(5\) | |
Cisco Adaptive Security Appliance Software | =8.6 | |
Cisco Adaptive Security Appliance Software | =8.6\(1\) | |
Cisco Adaptive Security Appliance Software | =8.6\(1.10\) | |
Cisco Adaptive Security Appliance Software | =9.0 | |
Cisco Adaptive Security Appliance Software | =9.1 | |
Cisco Adaptive Security Appliance Software | =8.0 | |
Cisco Adaptive Security Appliance Software | =8.0\(2\) | |
Cisco Adaptive Security Appliance Software | =8.0\(3\) | |
Cisco Adaptive Security Appliance Software | =8.0\(4\) | |
Cisco Adaptive Security Appliance Software | =8.0\(5\) | |
Cisco Adaptive Security Appliance Software | =8.0\(5.28\) | |
Cisco Adaptive Security Appliance Software | =8.0\(5.31\) | |
Cisco Adaptive Security Appliance Software | =8.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5515 is classified as a high severity vulnerability due to its potential to cause denial of service.
To mitigate CVE-2013-5515, upgrade to a Cisco Adaptive Security Appliance Software version that is 8.2(5.44) or later, 8.3(2.39) or later, and so on as specified in the advisory.
CVE-2013-5515 affects multiple versions of Cisco Adaptive Security Appliance Software, specifically versions prior to 8.2(5.44), 8.3(2.39), and several others listed in the advisory.
CVE-2013-5515 can be exploited by remote attackers to trigger a device reload, resulting in a denial of service.
While there are no official workarounds for CVE-2013-5515, ensuring proper access controls and limiting exposure may help reduce risk.