CVE-2015-6379
published 2015-11-25CVE-2015-6379: The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authenticated users to cause a denial of…
PriorityP427medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
1.51%
71.6th percentile
The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authenticated users to cause a denial of service (device crash) via a crafted XML document, aka Bug ID CSCut14223.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | asa | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xm5j-2w65-39cm: The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8
ghsa_unreviewed·2022-05-17
CVE-2015-6379 [MEDIUM] GHSA-xm5j-2w65-39cm: The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8
The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authenticated users to cause a denial of service (device crash) via a crafted XML document, aka Bug ID CSCut14223.
Cisco
Cisco ASA Management Interface XML Parser Denial of Service Vulnerability
vendor_cisco·2015-11-24·CVSS 6.8
CVE-2015-6379 [MEDIUM] CWE-399 Cisco ASA Management Interface XML Parser Denial of Service Vulnerability
Cisco ASA Management Interface XML Parser Denial of Service Vulnerability
A vulnerability in the XML parser of the management interface in Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause system instability and possibly crash an affected system.
The vulnerability is due to insufficient hardening of the XML parser code. An attacker could exploit this vulnerability by triggering the affected component to perform a read operation of a crafted XML file.
Cisco has released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151123-asa
Cisco
Cisco ASA Management Interface XML Parser Denial of Service Vulnerability
vendor_cisco
CVE-2015-6379 Cisco ASA Management Interface XML Parser Denial of Service Vulnerability
CVE-2015-6379: Cisco ASA Management Interface XML Parser Denial of Service Vulnerability
A vulnerability in the XML parser of the management interface in Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause system instability and possibly crash an affected system. The vulnerability is due to insufficient hardening of the XML parser code. An attacker could exploit this vulnerability by triggering the affected component to perform a read operation of a crafted XML file. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCut14223
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-11-25
Published