CVE-2015-6325Cisco Adaptive Security Appliance Software vulnerability

CWE-3996 documents6 sources
Severity
7.1HIGHNVD
EPSS
0.7%
top 28.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateMay 17

Description

Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.4), 9.2 before 9.2(4), 9.3 before 9.3(3.1), and 9.4 before 9.4(1.1) allows remote attackers to cause a denial of service (device reload) via a crafted DNS response, aka Bug ID CSCut03495.

CVSS vector

AV:N/AC:M/C:N/I:N/A:CExploitability: 8.6 | Impact: 6.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-qfrp-89jw-777c: Cisco Adaptive Security Appliance (ASA) software 72022-05-17
CVEList
CVE-2015-6325: Cisco Adaptive Security Appliance (ASA) software 72015-10-25

📋Vendor Advisories

1
Cisco
Cisco ASA Software DNS Denial of Service Vulnerability2015-10-21

📄Research Papers

1
arXiv
Software-Defined Adversarial Trajectory Sampling2017-04-30

💬Community

1
Bugzilla
CVE-2015-0223 qpid-cpp: anonymous access to qpidd cannot be prevented2015-01-27
CVE-2015-6325 — Cisco vulnerability | cvebase