CVE-2013-6682
published 2013-11-13CVE-2013-6682: The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates, which…
PriorityP427medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
0.75%
51.1th percentile
The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates, which allows remote attackers to cause a denial of service (connection-database corruption) via an invalid entry, aka Bug ID CSCui33299.
Affected
111 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | <= 9.0.3\(6\) | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
vendor_cisco6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance Phone Proxy Database Entry Manipulation Vulnerability
vendor_cisco·2013-11-11·CVSS 6.4
CVE-2013-6682 [MEDIUM] CWE-264 Cisco Adaptive Security Appliance Phone Proxy Database Entry Manipulation Vulnerability
Cisco Adaptive Security Appliance Phone Proxy Database Entry Manipulation Vulnerability
A vulnerability in the phone proxy feature of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to temporarily insert an invalid entry in the phone proxy connection database.
The vulnerability is due to the acceptance of an untrusted certificate. An attacker could exploit this vulnerability by submitting a crafted certificate to the phone proxy process. An exploit could allow the attacker to insert an invalid entry into the phone proxy connection database.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, it is likely that an attacker would need access to trusted, internal
GHSA
GHSA-j62m-465v-c87q: The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9
ghsa_unreviewed·2022-05-17
CVE-2013-6682 [MEDIUM] CWE-20 GHSA-j62m-465v-c87q: The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9
The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates, which allows remote attackers to cause a denial of service (connection-database corruption) via an invalid entry, aka Bug ID CSCui33299.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-11-13
Published