Skip to main content

Cisco ASA WebVPN Denial of Service Vulnerability

Last Update Date: 10 Feb 2015 09:45 Release Date: 10 Feb 2015 2997 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

A vulnerability has been identified in Cisco Adaptive Security Appliance (ASA), which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error in the Proxy Bypass Content Rewriter implementation within WebVPN and can be exploited to cause a crash.

Successful exploitation requires the use of webvpn with content rewrite configuration.


Impact

  • Denial of Service

System / Technologies affected

  • Versions prior to 9.1(.2)

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix.

Vulnerability Identifier


Source


Related Link