CVE-2015-6321
published 2015-11-06CVE-2015-6321: Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) devices…
PriorityP339high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.76%
84.7th percentile
Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) devices; before 9.1.0-032, 9.1.1 before 9.1.1-005, and 9.5.x before 9.5.0-025 on Content Security Management Appliance (SMA) devices; and before 7.7.0-725 and 8.x before 8.0.8-113 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets, aka Bug IDs CSCus79774, CSCus79777, and CSCzv95795.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asyncos_tcp_flood | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
| cisco | email_security_appliance | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco AsyncOS TCP Flood Denial of Service Vulnerability
vendor_cisco·2015-11-04·CVSS 7.1
CVE-2015-6321 [HIGH] CWE-399 Cisco AsyncOS TCP Flood Denial of Service Vulnerability
Cisco AsyncOS TCP Flood Denial of Service Vulnerability
A vulnerability in the network stack of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust all available memory, preventing the affected device from accepting new TCP connections.
The vulnerability is due to improper handling of TCP packets sent at a high rate. An attacker could exploit this vulnerability by sending crafted TCP packets to the affected system.
Note: A full device reload is needed to recover the system to an operational state.
Cisco has released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability. This advisory
Cisco
Cisco AsyncOS TCP Flood Denial of Service Vulnerability
vendor_cisco
CVE-2015-6321 Cisco AsyncOS TCP Flood Denial of Service Vulnerability
CVE-2015-6321: Cisco AsyncOS TCP Flood Denial of Service Vulnerability
A vulnerability in the network stack of Cisco AsyncOS for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA) and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust all available memory, preventing the affected device from accepting new TCP connections. The vulnerability is due to improper handling of TCP packets sent at a high rate. An attacker could exploit this vulnerability by sending crafted TCP packets to the affected system. Note: A full device reload is needed to recover the system to an operational state. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCus79774, CSCus
GHSA
GHSA-rmcx-cqh3-x8cj: Cisco AsyncOS before 8
ghsa_unreviewed·2022-05-17
CVE-2015-6321 [HIGH] GHSA-rmcx-cqh3-x8cj: Cisco AsyncOS before 8
Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) devices; before 9.1.0-032, 9.1.1 before 9.1.1-005, and 9.5.x before 9.5.0-025 on Content Security Management Appliance (SMA) devices; and before 7.7.0-725 and 8.x before 8.0.8-113 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets, aka Bug IDs CSCus79774, CSCus79777, and CSCzv95795.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151104-aoshttp://www.securitytracker.com/id/1034060http://www.securitytracker.com/id/1034061http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151104-aoshttp://www.securitytracker.com/id/1034060http://www.securitytracker.com/id/1034061
2015-11-06
Published