CVE-2012-2474Sensitive Information Exposure in Cisco Adaptive Security Appliance Software

Severity
4.0MEDIUMNVD
EPSS
0.4%
top 41.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 6
Latest updateMay 17

Description

Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 allows remote authenticated users to cause a denial of service (memory consumption and blank response page) by using the clientless WebVPN feature, aka Bug ID CSCth34278.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-mgcq-2wq9-xqxh: Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 82022-05-17
CVEList
CVE-2012-2474: Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 82012-08-06

📋Vendor Advisories

1
Cisco
Cisco ASA 5500 Series Adaptive Security Appliance Clientless WebVPN Remote Denial of Service Vulnerability2012-08-09
CVE-2012-2474 — Sensitive Information Exposure in Cisco | cvebase