CVE-2015-0742
published 2015-05-21CVE-2015-0742: The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105)…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.34%
87.4th percentile
The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105), 9.3(2.100), 9.4(0.115), 100.13(0.21), 100.13(20.3), 100.13(21.9), and 100.14(1.1) does not properly implement multicast-forwarding registration, which allows remote attackers to cause a denial of service (forwarding outage) via a crafted multicast packet, aka Bug ID CSCus74398.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7qcp-rc3f-jqjv: The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9
ghsa_unreviewed·2022-05-17
CVE-2015-0742 [MEDIUM] GHSA-7qcp-rc3f-jqjv: The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9
The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105), 9.3(2.100), 9.4(0.115), 100.13(0.21), 100.13(20.3), 100.13(21.9), and 100.14(1.1) does not properly implement multicast-forwarding registration, which allows remote attackers to cause a denial of service (forwarding outage) via a crafted multicast packet, aka Bug ID CSCus74398.
Cisco
Cisco Adaptive Security Appliance Protocol Independent Multicast Registration Vulnerability
vendor_cisco·2015-05-20·CVSS 5.0
CVE-2015-0742 [MEDIUM] CWE-399 Cisco Adaptive Security Appliance Protocol Independent Multicast Registration Vulnerability
Cisco Adaptive Security Appliance Protocol Independent Multicast Registration Vulnerability
A vulnerability in the Protocol Independent Multicast (PIM) application of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to disrupt the multicast traffic forwarding on the affected device via a denial-of-service (DoS) attack.
The vulnerability is due to an inconsistency in how the PIM registration is implemented for multicast forwarding. An attacker could exploit this vulnerability by sending a crafted multicast packet to the affected device. An exploit could allow the attacker to disrupt the multicast forwarding via a DoS attack.
Cisco has confirmed the vulnerability and software updates are available.
To exploit this vulnerability, an attacker may
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-05-21
Published