CVE-2013-3382Improper Input Validation in Cisco Adaptive Security Appliance

Severity
7.8HIGHNVD
EPSS
0.4%
top 37.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26
Latest updateMay 17

Description

The Next-Generation Firewall (aka NGFW, formerly CX Context-Aware Security) module 9.x before 9.1.1.9 and 9.1.2.x before 9.1.2.12 for Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (device reload or traffic-processing outage) via fragmented (1) IPv4 or (2) IPv6 traffic, aka Bug ID CSCue88387.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-cmvr-qw2c-gpqq: The Next-Generation Firewall (aka NGFW, formerly CX Context-Aware Security) module 92022-05-17
CVEList
CVE-2013-3382: The Next-Generation Firewall (aka NGFW, formerly CX Context-Aware Security) module 92013-06-26

📋Vendor Advisories

1
Cisco
Cisco ASA Next-Generation Firewall Fragmented Traffic Denial of Service Vulnerability2013-06-26
CVE-2013-3382 — Improper Input Validation in Cisco | cvebase