imPC@ndo EN

Tracker / CVE-2019-12693

CVE-2019-12693

Media 4.9

A vulnerability in the Secure Copy (SCP) feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to the use of an incorrect data type for a length variable. An attacker could exploit this vulnerability by initiating the transfer of a large file to an affected device via SCP. To exploit this vulnerability, the attacker would need to have valid privilege level 15 credentials on the affected device. A successful exploit could allow the attacker to cause the length variable to roll over, which could cause the affected device to crash.

Prodotti e versioni affette

cisco adaptive_security_appliance · … → 9.6.4.30
cisco adaptive_security_appliance_software · 9.10 → 9.10.1.22
cisco adaptive_security_appliance_software · 9.12 → 9.12.2.1
cisco adaptive_security_appliance_software · 9.7 → 9.8.4
cisco adaptive_security_appliance_software · 9.9 → 9.9.2.50

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti