imPC@ndo IT

Tracker / CVE-2012-0353

CVE-2012-0353

High 7.1

The UDP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.0 before 8.0(5.25), 8.1 before 8.1(2.50), 8.2 before 8.2(5.5), 8.3 before 8.3(2.22), 8.4 before 8.4(2.1), and 8.5 before 8.5(1.2) does not properly handle flows, which allows remote attackers to cause a denial of service (device reload) via a crafted series of (1) IPv4 or (2) IPv6 UDP packets, aka Bug ID CSCtq10441.

Affected products and versions

cisco 5500_series_adaptive_security_appliance
cisco adaptive_security_appliance_software
cisco catalyst_6500
cisco catalyst_6503-e
cisco catalyst_6504-e
cisco catalyst_6506-e
cisco catalyst_6509-e
cisco catalyst_6509-neb-a
cisco catalyst_6509-v-e
cisco catalyst_6513
cisco catalyst_6513-e

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References