CVE-2015-4321Improper Input Validation in Cisco Adaptive Security Appliance Software

Severity
5.0MEDIUMNVD
EPSS
0.2%
top 56.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 20
Latest updateMay 17

Description

The Unicast Reverse Path Forwarding (uRPF) implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(1.50), 9.3(2.100), 9.3(3), and 9.4(1) mishandles cases where an IP address belongs to an internal interface but is also in the ASA routing table, which allows remote attackers to bypass uRPF validation via spoofed packets, aka Bug ID CSCuv60724.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-f88v-743w-mgc8: The Unicast Reverse Path Forwarding (uRPF) implementation in Cisco Adaptive Security Appliance (ASA) Software 92022-05-17
CVEList
CVE-2015-4321: The Unicast Reverse Path Forwarding (uRPF) implementation in Cisco Adaptive Security Appliance (ASA) Software 92015-08-20

📋Vendor Advisories

1
Cisco
Cisco ASA Unicast Reverse Path Forwarding (uRPF) Bypass Vulnerability2015-08-12
CVE-2015-4321 — Improper Input Validation in Cisco | cvebase