| PROBLEM: | Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security
Appliances: 1) Windows NT domain authentication bypass; 2) IPv6 Denial of Service; and 3) Crypto Accelerator memory leak. NOTE: These vulnerabilities are independent of each other. A device may be affected by one vulnerability and not affected by another. |
| PLATFORM: | Cisco ASA and Cisco PIX |
| DAMAGE: | May allow an attacker to successfully connect to the Cisco ASA via remote access IPSec or SSL-based VPN which could result in a sustained DoS condition. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. A remote intruder could make a VPN connection to a network without needing to authenticate. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
4.3 3.7 (AV:N/AC:M/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C) |
| LINKS: | |
| DOE-CIRC BULLETIN: | http://doecirc.energy.gov/ciac/bulletins/t-023.shtml |
| ORIGINAL BULLETIN: | http://www.cisco.com/en/US/products/products_security_advisory09186a0080a183ba.shtml |
| CVE: | CVE-2008-3815 CVE-2008-3816 CVE-2008-3817 |
[***** Start Cisco Security Advisory Document ID: 108009 *****]
Summary
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
Cisco Security Procedures
Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security Appliances. This security advisory outlines details of these vulnerabilities:
Note: These vulnerabilities are independent of each other. A device may be affected by one vulnerability and not affected by another.
Cisco has released free software updates that address these vulnerabilities. Workarounds that mitigate some of these vulnerabilities are available.
This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20081022-asa.shtml.
[Expand all sections] [Collapse all sections]
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
[***** End Cisco Security Advisory Document ID: 108009 *****]
Voice: +1 866-941-2472 (7 x 24)
E-mail: doecirc@doecirc.energy.gov
World Wide Web: http://www.doecirc.energy.gov/