CVE-2012-2474
published 2012-08-06CVE-2012-2474: Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 allows remote authenticated users to cause a denial…
PriorityP415medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
1.38%
69.1th percentile
Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 allows remote authenticated users to cause a denial of service (memory consumption and blank response page) by using the clientless WebVPN feature, aka Bug ID CSCth34278.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mgcq-2wq9-xqxh: Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8
ghsa_unreviewed·2022-05-17
CVE-2012-2474 [MEDIUM] CWE-200 GHSA-mgcq-2wq9-xqxh: Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8
Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 allows remote authenticated users to cause a denial of service (memory consumption and blank response page) by using the clientless WebVPN feature, aka Bug ID CSCth34278.
Cisco
Cisco ASA 5500 Series Adaptive Security Appliance Clientless WebVPN Remote Denial of Service Vulnerability
vendor_cisco·2012-08-09·CVSS 4.0
CVE-2012-2474 [MEDIUM] CWE-399 Cisco ASA 5500 Series Adaptive Security Appliance Clientless WebVPN Remote Denial of Service Vulnerability
Cisco ASA 5500 Series Adaptive Security Appliance Clientless WebVPN Remote Denial of Service Vulnerability
The Cisco ASA 5500 Series Adaptive Security Appliance contains a vulnerability that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to the improper handling of user-supplied requests by an affected system when configured to use the clientless WebVPN feature. An authenticated, remote attacker can exploit this vulnerability by submitting requests while the clientless WebVPN feature is enabled, causing excessive memory consumption. If successful, an attacker could cause a blank response page, resulting in a DoS condition.
Cisco has confirmed this vulnerability and released software updates.
To successfully exploit
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-08-06
Published