CVE-2013-6707
published 2013-12-07CVE-2013-6707: Memory leak in the connection-manager implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to cause a…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.50%
82.9th percentile
Memory leak in the connection-manager implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to cause a denial of service (multi-protocol management outage) by making multiple management session requests, aka Bug ID CSCug33233.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | <= 9.1\(3\) | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance Management Connections Denial of Service Vulnerability
vendor_cisco·2013-12-06·CVSS 4.3
CVE-2013-6707 [MEDIUM] CWE-399 Cisco Adaptive Security Appliance Management Connections Denial of Service Vulnerability
Cisco Adaptive Security Appliance Management Connections Denial of Service Vulnerability
A vulnerability in the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an affected system to become unresponsive to management session requests via SSH, Telnet, HTTP, and HTTPS.
The vulnerability is due to a memory leak in the connection manager code when management flows are created. An attacker could exploit this vulnerability by creating several management session requests.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker may need access to trusted internal networks, in which the targeted device may reside, to create management session requests. This acc
GHSA
GHSA-wjrw-qp67-6h86: Memory leak in the connection-manager implementation in Cisco Adaptive Security Appliance (ASA) Software 9
ghsa_unreviewed·2022-05-17
CVE-2013-6707 [MEDIUM] CWE-772 GHSA-wjrw-qp67-6h86: Memory leak in the connection-manager implementation in Cisco Adaptive Security Appliance (ASA) Software 9
Memory leak in the connection-manager implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to cause a denial of service (multi-protocol management outage) by making multiple management session requests, aka Bug ID CSCug33233.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/100682http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6707http://tools.cisco.com/security/center/viewAlert.x?alertId=32065http://www.securityfocus.com/bid/64148http://www.securitytracker.com/id/1029441https://exchange.xforce.ibmcloud.com/vulnerabilities/89442http://osvdb.org/100682http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-6707http://tools.cisco.com/security/center/viewAlert.x?alertId=32065http://www.securityfocus.com/bid/64148http://www.securitytracker.com/id/1029441https://exchange.xforce.ibmcloud.com/vulnerabilities/89442
2013-12-07
Published