PT-2005-4539 · Cisco · Cisco Asa
Amin Tora
·
Published
2005-11-24
·
Updated
2023-08-11
·
CVE-2005-3788
CVSS v2.0
5.4
Medium
| Vector | AV:N/AC:H/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Adaptive Security Appliance (ASA) versions 7.0(0) through 7.0(4)
Description
The issue is related to a race condition that occurs when the Cisco Adaptive Security Appliance (ASA) is running with an Active/Standby configuration and the failover LAN interface fails. This allows remote attackers to cause a denial of service by sending spoofed ARP responses from an IP address of an active firewall, preventing the standby firewall from becoming active.
Recommendations
For Cisco Adaptive Security Appliance (ASA) versions 7.0(0) through 7.0(4), consider configuring the failover setup to use a more secure method to prevent spoofed ARP responses, and ensure that the standby firewall can become active even if the failover LAN interface fails.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Asa