CVE-2013-1152
published 2013-04-11CVE-2013-1152: Cisco Adaptive Security Appliances (ASA) devices with software 9.0 before 9.0(1.2) allow remote attackers to cause a denial of service (device reload) via a…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.53%
72.0th percentile
Cisco Adaptive Security Appliances (ASA) devices with software 9.0 before 9.0(1.2) allow remote attackers to cause a denial of service (device reload) via a crafted field in a DNS message, aka Bug ID CSCuc80080.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | asa | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco·2013-04-10·CVSS 7.8
CVE-2013-1149 [HIGH] CWE-399 Multiple Vulnerabilities in Cisco ASA Software
Multiple Vulnerabilities in Cisco ASA Software
Cisco ASA Software is affected by the following vulnerabilities:
IKE Version 1 Denial of Service Vulnerability
Crafted URL Denial of Service Vulnerability
Denial of Service During Validation of Crafted Certificates
DNS Inspection Denial of Service Vulnerability
These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the others.
Successful exploitation of any of these vulnerabilities may result in a reload of an affected device, leading to a denial of service (DoS) condition.
Cisco has released software updates that address these vulnerabilities. Workarounds are available for some of these vulnerabilities.
This advisory is available at the following link:
https:
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco
CVE-2013-1152 Multiple Vulnerabilities in Cisco ASA Software
CVE-2013-1152: Multiple Vulnerabilities in Cisco ASA Software
Cisco ASA Software is affected by the following vulnerabilities: IKE Version 1 Denial of Service Vulnerability Crafted URL Denial of Service Vulnerability Denial of Service During Validation of Crafted Certificates DNS Inspection Denial of Service Vulnerability These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the others. Successful exploitation of any of these vulnerabilities may result in a reload of an affected device, leading to a denial of service (DoS) condition. Cisco has released software updates that address these vulnerabilities.
CWE: CWE-399, CWE-399
Bug IDs: CSCub85692, CSCuc72408, CSCuc80080, CSCub85692, CSCuc72408
GHSA
GHSA-qmcw-879x-f67w: Cisco Adaptive Security Appliances (ASA) devices with software 9
ghsa_unreviewed·2022-05-17
CVE-2013-1152 [HIGH] GHSA-qmcw-879x-f67w: Cisco Adaptive Security Appliances (ASA) devices with software 9
Cisco Adaptive Security Appliances (ASA) devices with software 9.0 before 9.0(1.2) allow remote attackers to cause a denial of service (device reload) via a crafted field in a DNS message, aka Bug ID CSCuc80080.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4213 JBoss ejb-client: Session fixation due improper connection caching
bugzilla·2013-07-17·CVSS 6.4
CVE-2013-4213 [MEDIUM] CVE-2013-4213 JBoss ejb-client: Session fixation due improper connection caching
CVE-2013-4213 JBoss ejb-client: Session fixation due improper connection caching
A flaw was discovered in the way connections for remote EJB invocations via the EJB client API were cached on the server. A remote attacker could exploit this flaw by using an EJB client to get a previously authenticated connection.
Discussion:
Acknowledgements:
This issue was discovered by Wolf-Dieter Fink of the Red Hat GSS Team.
---
This issue has been addressed in following products:
Red Hat JBoss Enterprise Application Platform 6.1.0
Via RHSA-2013:1152 https://rhn.redhat.com/errata/RHSA-2013-1152.html
---
This issue has been addressed in following products:
JBEAP 6 for RHEL 5
JBEAP 6 for RHEL 6
Via RHSA-2013:1151 https://rhn.redhat.com/errata/RHSA-2013-1151.html
---
This issue has been addre
Bugzilla
CVE-2013-4128 JBoss remote-naming: Session fixation due improper connection caching
bugzilla·2013-07-16·CVSS 6.4
CVE-2013-4128 [MEDIUM] CVE-2013-4128 JBoss remote-naming: Session fixation due improper connection caching
CVE-2013-4128 JBoss remote-naming: Session fixation due improper connection caching
A flaw was discovered in the way connections for remote EJB invocations via the remote-naming project were cached on the server. A remote attacker could exploit this flaw by using an EJB client to get a previously authenticated connection.
Discussion:
Acknowledgements:
This issue was discovered by Wolf-Dieter Fink of the Red Hat GSS Team.
---
This issue has been addressed in following products:
Red Hat JBoss Enterprise Application Platform 6.1.0
Via RHSA-2013:1152 https://rhn.redhat.com/errata/RHSA-2013-1152.html
---
This issue has been addressed in following products:
JBEAP 6 for RHEL 5
JBEAP 6 for RHEL 6
Via RHSA-2013:1151 https://rhn.redhat.com/errata/RHSA-2013-1151.html
---
This issue has
2013-04-11
Published