CVE-2015-0678
published 2015-04-11CVE-2015-0678: The virtualization layer in Cisco ASA FirePOWER Software before 5.3.1.2 and 5.4.x before 5.4.0.1 and ASA Context-Aware (CX) Software before 9.3.2.1-9 allows…
PriorityP339high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.32%
81.5th percentile
The virtualization layer in Cisco ASA FirePOWER Software before 5.3.1.2 and 5.4.x before 5.4.0.1 and ASA Context-Aware (CX) Software before 9.3.2.1-9 allows remote attackers to cause a denial of service (device reload) by rapidly sending crafted packets to the management interface, aka Bug IDs CSCus11007 and CSCun56954.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_firepower_services_and_cisco_asa_cx_services_crafted_packets | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ASA FirePOWER Services and Cisco ASA CX Services Crafted Packets Denial of Service Vulnerability
vendor_cisco·2015-04-08·CVSS 7.8
CVE-2015-0678 [HIGH] Cisco ASA FirePOWER Services and Cisco ASA CX Services Crafted Packets Denial of Service Vulnerability
Cisco ASA FirePOWER Services and Cisco ASA CX Services Crafted Packets Denial of Service Vulnerability
A vulnerability in the virtualization layer of the Cisco ASA FirePOWER Services and Cisco ASA Context Aware (CX) Services could allow an unauthenticated, remote attacker to cause
the a reload of the affected system.
Cisco has released software updates that address this vulnerability. The resolution includes upgrading the Cisco ASA FirePOWER Services Software or the Cisco ASA CX Services Software and the Cisco ASA Software. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150408-cxfp
Note: Cisco ASA Software is affected by several othe
Cisco
Cisco ASA FirePOWER Services and Cisco ASA CX Services Crafted Packets Denial of Service Vulnerability
vendor_cisco
CVE-2015-0678 Cisco ASA FirePOWER Services and Cisco ASA CX Services Crafted Packets Denial of Service Vulnerability
CVE-2015-0678: Cisco ASA FirePOWER Services and Cisco ASA CX Services Crafted Packets Denial of Service Vulnerability
A vulnerability in the virtualization layer of the Cisco ASA FirePOWER Services and Cisco ASA Context Aware (CX) Services could allow an unauthenticated, remote attacker to cause the a reload of the affected system. Cisco has released software updates that address this vulnerability. The resolution includes upgrading the Cisco ASA FirePOWER Services Software or the Cisco ASA CX Services Software and the Cisco ASA Software.
Bug IDs: CSCun56954, CSCuo58584, CSCus11007, CSCun56954, CSCuo58584
GHSA
GHSA-5v87-2xc2-82hj: The virtualization layer in Cisco ASA FirePOWER Software before 5
ghsa_unreviewed·2022-05-17
CVE-2015-0678 [HIGH] CWE-20 GHSA-5v87-2xc2-82hj: The virtualization layer in Cisco ASA FirePOWER Software before 5
The virtualization layer in Cisco ASA FirePOWER Software before 5.3.1.2 and 5.4.x before 5.4.0.1 and ASA Context-Aware (CX) Software before 9.3.2.1-9 allows remote attackers to cause a denial of service (device reload) by rapidly sending crafted packets to the management interface, aka Bug IDs CSCus11007 and CSCun56954.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-11
Published