CVE-2007-2464
published 2007-05-02CVE-2007-2464: Race condition in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)19, when using "clientless SSL VPNs," allows remote…
PriorityP423high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
2.94%
85.6th percentile
Race condition in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)19, when using "clientless SSL VPNs," allows remote attackers to cause a denial of service (device reload) via "non-standard SSL sessions."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | <= 7.2.2 | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | pix | <= 7.2 | — |
| cisco | pix | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
LDAP and VPN Vulnerabilities in PIX and ASA Appliances
vendor_cisco·2007-05-02·CVSS 8.0
CVE-2007-2462 [HIGH] CWE-287 LDAP and VPN Vulnerabilities in PIX and ASA Appliances
LDAP and VPN Vulnerabilities in PIX and ASA Appliances
Multiple vulnerabilities exist in the Cisco Adaptive Security Appliance
(ASA) and PIX security appliances. These vulnerabilities include two
Lightweight Directory Access Protocol (LDAP) authentication bypass
vulnerabilities and two denial of service (DoS) vulnerabilities.
The Lightweight Directory Access Protocol (LDAP) authentication bypass
vulnerabilities are caused by a specific processing path followed when the
device is setup to use a Lightweight Directory Access Protocol (LDAP)
authentication server. These vulnerabilities may allow unauthenticated users to
access either the internal network or the device itself.
The two DoS vulnerabilities may be triggered when devices are
terminating Virtual Private Networks (VPN). These deni
Cisco
LDAP and VPN Vulnerabilities in PIX and ASA Appliances
vendor_cisco
CVE-2007-2464 LDAP and VPN Vulnerabilities in PIX and ASA Appliances
CVE-2007-2464: LDAP and VPN Vulnerabilities in PIX and ASA Appliances
Multiple vulnerabilities exist in the Cisco Adaptive Security Appliance (ASA) and PIX security appliances. These vulnerabilities include two Lightweight Directory Access Protocol (LDAP) authentication bypass vulnerabilities and two denial of service (DoS) vulnerabilities. The Lightweight Directory Access Protocol (LDAP) authentication bypass vulnerabilities are caused by a specific processing path followed when the device is setup to use a Lightweight Directory Access Protocol (LDAP) authentication server. These vulnerabilities may allow unauthenticated users to access either the internal network or the device itself. The two DoS vulnerabilities may be triggered when devices are terminating Virtual Private Networks (VPN)
GHSA
GHSA-rrvv-gf86-xrp2: Race condition in Cisco Adaptive Security Appliance (ASA) and PIX 7
ghsa_unreviewed·2022-05-01
CVE-2007-2464 [HIGH] GHSA-rrvv-gf86-xrp2: Race condition in Cisco Adaptive Security Appliance (ASA) and PIX 7
Race condition in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)19, when using "clientless SSL VPNs," allows remote attackers to cause a denial of service (device reload) via "non-standard SSL sessions."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/25109http://www.cisco.com/en/US/products/products_security_advisory09186a0080833166.shtmlhttp://www.kb.cert.org/vuls/id/337508http://www.osvdb.org/35333http://www.securityfocus.com/bid/23768http://www.vupen.com/english/advisories/2007/1636https://exchange.xforce.ibmcloud.com/vulnerabilities/34023http://secunia.com/advisories/25109http://www.cisco.com/en/US/products/products_security_advisory09186a0080833166.shtmlhttp://www.kb.cert.org/vuls/id/337508http://www.osvdb.org/35333http://www.securityfocus.com/bid/23768http://www.vupen.com/english/advisories/2007/1636https://exchange.xforce.ibmcloud.com/vulnerabilities/34023
2007-05-02
Published