First published: Sat Apr 11 2015(Updated: )
The virtualization layer in Cisco ASA FirePOWER Software before 5.3.1.2 and 5.4.x before 5.4.0.1 and ASA Context-Aware (CX) Software before 9.3.2.1-9 allows remote attackers to cause a denial of service (device reload) by rapidly sending crafted packets to the management interface, aka Bug IDs CSCus11007 and CSCun56954.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco ASA FirePOWER | =5.3.1 | |
Cisco ASA FirePOWER | =5.3.1.1 | |
Cisco ASA FirePOWER | =5.4.0 | |
Cisco ASA CX Context-Aware Security | =9.0.1 | |
Cisco ASA CX Context-Aware Security | =9.0.1-40 | |
Cisco ASA CX Context-Aware Security | =9.0.2 | |
Cisco ASA CX Context-Aware Security | =9.0.2-68 | |
Cisco ASA CX Context-Aware Security | =9.0_base | |
Cisco ASA CX Context-Aware Security | =9.1.2-29 | |
Cisco ASA CX Context-Aware Security | =9.1.2-42 | |
Cisco ASA CX Context-Aware Security | =9.1.3-8 | |
Cisco ASA CX Context-Aware Security | =9.1.3-10 | |
Cisco ASA CX Context-Aware Security | =9.1.3-13 | |
Cisco ASA CX Context-Aware Security | =9.2.1-1 | |
Cisco ASA CX Context-Aware Security | =9.2.1-2 | |
Cisco ASA CX Context-Aware Security | =9.2.1-3 | |
Cisco ASA CX Context-Aware Security | =9.2.1-4 | |
Cisco ASA CX Context-Aware Security | =9.3\(1.1.112\) | |
Cisco ASA CX Context-Aware Security | =9.3.1-1 | |
Cisco ASA CX Context-Aware Security | =9.3.2-1 | |
Cisco ASA CX Context-Aware Security | =9.3_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0678 has a high severity rating as it allows remote attackers to trigger a denial of service.
To fix CVE-2015-0678, you should upgrade Cisco ASA FirePOWER Software to version 5.3.1.2 or higher, or 5.4.0.1 or higher, and apply the necessary patches.
CVE-2015-0678 affects Cisco ASA with FirePOWER Services versions prior to 5.3.1.2 and 5.4.x versions before 5.4.0.1, as well as Cisco ASA CX Context-Aware Software versions prior to 9.3.2.1-9.
CVE-2015-0678 enables remote attackers to perform a denial of service attack by sending specially crafted packets.
There are no known workarounds for CVE-2015-0678; the only remediation is to apply the appropriate software updates.