PT-2015-1628 · Cisco · Cisco Asa

Published

2015-07-02

·

Updated

2023-08-11

·

CVE-2015-4239

CVSS v2.0

6.1

Medium

VectorAV:A/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Adaptive Security Appliance (ASA) Software versions 9.3(2.243) and 9.13(0.21)
Description The issue is related to resource management errors in the Cisco Adaptive Security Appliance, allowing an unauthenticated, adjacent attacker to cause a denial of service by sending crafted OSPFv2 packets on the local network. This can lead to a device reload.
Recommendations For version 9.3(2.243), update to a fixed version to resolve the issue. For version 9.13(0.21), update to a fixed version to resolve the issue. As a temporary workaround, consider restricting access to the OSPFv2 protocol to minimize the risk of exploitation.

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2015-10971
CVE-2015-4239

Affected Products

Cisco Asa