CVE-2007-2461
published 2007-05-02CVE-2007-2461: The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 allows remote attackers to cause a denial of service (dropped packets) via a…
PriorityP427high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
4.37%
90.2th percentile
The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 allows remote attackers to cause a denial of service (dropped packets) via a DHCPREQUEST or DHCPINFORM message that causes multiple DHCPACK messages to be sent from DHCP servers to the agent, which consumes the memory allocated for a local buffer. NOTE: this issue only occurs when multiple DHCP servers are used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | pix | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vwjv-mqrc-fc89: The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7
ghsa_unreviewed·2022-05-01
CVE-2007-2461 [HIGH] GHSA-vwjv-mqrc-fc89: The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7
The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 allows remote attackers to cause a denial of service (dropped packets) via a DHCPREQUEST or DHCPINFORM message that causes multiple DHCPACK messages to be sent from DHCP servers to the agent, which consumes the memory allocated for a local buffer. NOTE: this issue only occurs when multiple DHCP servers are used.
Cisco
Cisco PIX/ASA DHCP Relay Agent Memory Leak Vulnerability
vendor_cisco·2007-05-02·CVSS 7.8
CVE-2007-2461 [HIGH] CWE-399 Cisco PIX/ASA DHCP Relay Agent Memory Leak Vulnerability
Cisco PIX/ASA DHCP Relay Agent Memory Leak Vulnerability
Cisco PIX and Adaptive Security Appliance (ASA) software versions 7.2(1) through 7.2(2.14) contain a vulnerability that could allow an unauthenticated, remote attacker to cause an affected device to stop forwarding traffic.
This vulnerability exists due to an error when handling specific DHCP packets under certain configurations. An unauthenticated, remote attacker could exploit this vulnerability by sending a large number of DHCP requests to the affected device, causing the device to consume available memory resources for processing traffic. When the device exhausts available memory, it ceases to forward traffic, resulting in a denial of service (DoS) condition.
Cisco has confirmed this vulnerability and released software updates.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/25109http://www.cisco.com/en/US/products/products_security_response09186a0080833172.htmlhttp://www.kb.cert.org/vuls/id/530057http://www.osvdb.org/35330http://www.securityfocus.com/bid/23763http://www.securitytracker.com/id?1017999http://www.securitytracker.com/id?1018000http://www.vupen.com/english/advisories/2007/1635https://exchange.xforce.ibmcloud.com/vulnerabilities/34026http://secunia.com/advisories/25109http://www.cisco.com/en/US/products/products_security_response09186a0080833172.htmlhttp://www.kb.cert.org/vuls/id/530057http://www.osvdb.org/35330http://www.securityfocus.com/bid/23763http://www.securitytracker.com/id?1017999http://www.securitytracker.com/id?1018000http://www.vupen.com/english/advisories/2007/1635https://exchange.xforce.ibmcloud.com/vulnerabilities/34026
2007-05-02
Published