cbcvebase.
CVE-2012-4661
published 2012-10-29

CVE-2012-4661: Stack-based buffer overflow in the DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module…

PriorityP258critical9CVSS 2.0
AVNACMAuNCCIPAC
EPSS
4.05%
89.6th percentile
Stack-based buffer overflow in the DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2.34), 8.4 before 8.4(4.4), 8.5 before 8.5(1.13), and 8.6 before 8.6(1.3) and the Firewall Services Module (FWSM) 4.1 before 4.1(9) in Cisco Catalyst 6500 series switches and 7600 series routers might allow remote attackers to execute arbitrary code via a crafted DCERPC packet, aka Bug IDs CSCtr21359 and CSCtr27522.

Affected

13 ranges
VendorProductVersion rangeFixed in
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoadaptive_security_appliance_software
ciscoasa_5500_series_adaptive_security_appliances_and_cisco_catalyst_6500_series_asa

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger detection on crafted DCERPC packets targeting the DCERPC inspection engine on Cisco ASA/FWSM devices; a malformed DCERPC packet can cause a stack-based buffer overflow enabling arbitrary code execution
  • Monitor for unexpected device reloads or stack overflow indicators on Cisco ASA 5500 / Catalyst 6500 ASASM / FWSM devices with DCERPC inspection enabled, as exploitation may manifest as a reload or arbitrary command execution
  • Unauthenticated remote exploitation is possible; no authentication required to send the malicious DCERPC packet — alert on anomalous DCERPC traffic from untrusted/external sources toward ASA/FWSM inspection interfaces
  • ·Vulnerability is only exploitable when DCERPC inspection is enabled on the device; disabling DCERPC inspection removes the attack surface
  • ·Affected ASA software versions: 8.3 before 8.3(2.34), 8.4 before 8.4(4.4), 8.5 before 8.5(1.13), and 8.6 before 8.6(1.3); FWSM affected version: 4.1 before 4.1(9)
  • ·These vulnerabilities are independent of each other; a release affected by one vulnerability may not be affected by the others listed in the same advisory
  • ·Cisco internal bug IDs for tracking and patch verification: CSCtr21359 (ASA) and CSCtr27522 (FWSM) for the buffer overflow; additional related bugs CSCtr21346 and CSCtr21376 cover DoS variants

CVSS provenance

nvdv2.09.0CRITICALAV:N/AC:M/Au:N/C:C/I:P/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.