CVE-2013-5568
published 2013-11-13CVE-2013-5568: The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier allows remote attackers to cause a denial of service…
PriorityP428high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
1.17%
64.2th percentile
The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier allows remote attackers to cause a denial of service (device reload) via crafted update data, aka Bug ID CSCui33308.
Affected
111 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | <= 9.0.3\(6\) | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5rr6-459r-623v: The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9
ghsa_unreviewed·2022-05-17
CVE-2013-5568 [HIGH] CWE-20 GHSA-5rr6-459r-623v: The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9
The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier allows remote attackers to cause a denial of service (device reload) via crafted update data, aka Bug ID CSCui33308.
Cisco
Cisco Adaptive Security Appliance Auto-Update Denial of Service Vulnerability
vendor_cisco·2013-11-11·CVSS 7.1
CVE-2013-5568 [HIGH] CWE-20 Cisco Adaptive Security Appliance Auto-Update Denial of Service Vulnerability
Cisco Adaptive Security Appliance Auto-Update Denial of Service Vulnerability
A vulnerability in the auto-update feature of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause a reload of the ASA.
The vulnerability is due to insufficient input validation of auto-update data. An attacker could exploit this vulnerability by submitting crafted data to the auto-update process. An exploit could allow the attacker to cause the ASA to reload.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-11-13
Published