CVE-2019-1705: Cisco Adaptive Security Appliance Software VPN Denial of Service Vulnerability
A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-1705?
CVE-2019-1705 is a vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software.
How does CVE-2019-1705 affect Cisco ASA Software?
CVE-2019-1705 could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on the remote access VPN services of Cisco ASA Software.
What is the severity of CVE-2019-1705?
CVE-2019-1705 has a severity rating of 5.9 (medium).
Which versions of Cisco ASA Software are affected by CVE-2019-1705?
Cisco ASA Software versions between 9.4 and 9.4.4.34, between 9.5 and 9.6.4.25, between 9.7 and 9.8.4, between 9.9 and 9.9.2.50, and between 9.10 and 9.10.1.17 are affected by CVE-2019-1705.
How can I fix CVE-2019-1705?
Cisco has released software updates to address the vulnerability. It is recommended to update to the latest available version of Cisco ASA Software.