CVE-2013-6691 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Cisco Adaptive Security Appliance Software

Severity
6.8MEDIUMNVD
EPSS
0.6%
top 30.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateMay 13

Description

The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0(.4.1) and earlier allows remote CIFS servers to cause a denial of service (device reload) via a long share list, aka Bug ID CSCuj83344.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 8.0 | Impact: 6.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-6j8f-mqp2-w454: The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9↗2022-05-13
â–¶
CVEList
CVE-2013-6691: The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9↗2014-07-14
â–¶

📋Vendor Advisories

1
Cisco
Cisco ASA CIFS Share Enumeration Denial of Service Vulnerability↗2014-07-14
â–¶
CVE-2013-6691 — Cisco vulnerability | cvebase