CVE-2013-6691
published 2014-07-14CVE-2013-6691: The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0(.4.1) and earlier allows remote CIFS servers to cause a denial of…
PriorityP429medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
1.70%
74.8th percentile
The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0(.4.1) and earlier allows remote CIFS servers to cause a denial of service (device reload) via a long share list, aka Bug ID CSCuj83344.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | <= 9.0\(4.1\) | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ASA CIFS Share Enumeration Denial of Service Vulnerability
vendor_cisco·2014-07-14·CVSS 6.8
CVE-2013-6691 [MEDIUM] CWE-119 Cisco ASA CIFS Share Enumeration Denial of Service Vulnerability
Cisco ASA CIFS Share Enumeration Denial of Service Vulnerability
A vulnerability in the WebVPN Common Internet File System (CIFS) access function of Cisco Adaptive
Security Appliance (ASA) could allow an authenticated, remote attacker
to trigger a reload of the affected device.
The vulnerability is
due to missing bounds checks on the response received from the CIFS
server when enumerating available shares. An attacker could exploit this
vulnerability by attempting to attain the list of shares from CIFS
servers that offer a large number of shares. Controlling a
CIFS server may also aid the attacker. An exploit could allow the attacker to
trigger a reload of the Cisco ASA, resulting in a denial of service (DoS) condition.
Cisco has confirmed the vulnerability in a security notice and rele
GHSA
GHSA-6j8f-mqp2-w454: The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9
ghsa_unreviewed·2022-05-13
CVE-2013-6691 [MEDIUM] CWE-119 GHSA-6j8f-mqp2-w454: The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9
The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0(.4.1) and earlier allows remote CIFS servers to cause a denial of service (device reload) via a long share list, aka Bug ID CSCuj83344.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6691http://tools.cisco.com/security/center/viewAlert.x?alertId=34921http://www.securityfocus.com/bid/68517http://www.securitytracker.com/id/1030565https://exchange.xforce.ibmcloud.com/vulnerabilities/94459http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6691http://tools.cisco.com/security/center/viewAlert.x?alertId=34921http://www.securityfocus.com/bid/68517http://www.securitytracker.com/id/1030565https://exchange.xforce.ibmcloud.com/vulnerabilities/94459
2014-07-14
Published