CVE-2016-1369
published 2016-05-05CVE-2016-1369: The Adaptive Security Appliance (ASA) 5585-X FirePOWER Security Services Processor (SSP) module for Cisco ASA with FirePOWER Services 5.3.1 through 6.0.0…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.93%
77.7th percentile
The Adaptive Security Appliance (ASA) 5585-X FirePOWER Security Services Processor (SSP) module for Cisco ASA with FirePOWER Services 5.3.1 through 6.0.0 misconfigures kernel logging, which allows remote attackers to cause a denial of service (resource consumption, and inspection outage or module outage) via a flood of crafted IP traffic, aka Bug ID CSCux19922.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_with_firepower_services_kernel_logging | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
| cisco | asa_with_firepower_services | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance with FirePOWER Services Kernel Logging Denial of Service Vulnerability
vendor_cisco·2016-05-04·CVSS 7.8
CVE-2016-1369 [HIGH] CWE-399 Cisco Adaptive Security Appliance with FirePOWER Services Kernel Logging Denial of Service Vulnerability
Cisco Adaptive Security Appliance with FirePOWER Services Kernel Logging Denial of Service Vulnerability
A vulnerability in the kernel logging configuration for Firepower System Software for the Adaptive Security Appliance (ASA) 5585-X FirePOWER Security Services Processor (SSP) module could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of system resources.
The vulnerability is due to the logging of certain IP packets. An attacker could exploit this vulnerability by sending a flood of specially crafted IP packets to the affected device. An exploit could allow the attacker to cause the Cisco FirePOWER module to cease inspecting traffic or go offline.
Cisco has released software updates that address this vulnerability. There
Cisco
Cisco Adaptive Security Appliance with FirePOWER Services Kernel Logging Denial of Service Vulnerability
vendor_cisco
CVE-2016-1369 Cisco Adaptive Security Appliance with FirePOWER Services Kernel Logging Denial of Service Vulnerability
CVE-2016-1369: Cisco Adaptive Security Appliance with FirePOWER Services Kernel Logging Denial of Service Vulnerability
A vulnerability in the kernel logging configuration for Firepower System Software for the Adaptive Security Appliance (ASA) 5585-X FirePOWER Security Services Processor (SSP) module could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of system resources. The vulnerability is due to the logging of certain IP packets. An attacker could exploit this vulnerability by sending a flood of specially crafted IP packets to the affected device. An exploit could allow the attacker to cause the Cisco FirePOWER module to cease inspecting traffic or go offline. Cisco has released software updates that address this vulnerab
GHSA
GHSA-65p4-8967-8v6f: The Adaptive Security Appliance (ASA) 5585-X FirePOWER Security Services Processor (SSP) module for Cisco ASA with FirePOWER Services 5
ghsa_unreviewed·2022-05-17
CVE-2016-1369 [HIGH] GHSA-65p4-8967-8v6f: The Adaptive Security Appliance (ASA) 5585-X FirePOWER Security Services Processor (SSP) module for Cisco ASA with FirePOWER Services 5
The Adaptive Security Appliance (ASA) 5585-X FirePOWER Security Services Processor (SSP) module for Cisco ASA with FirePOWER Services 5.3.1 through 6.0.0 misconfigures kernel logging, which allows remote attackers to cause a denial of service (resource consumption, and inspection outage or module outage) via a flood of crafted IP traffic, aka Bug ID CSCux19922.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-05-05
Published