CVE-2016-1445
published 2016-07-12CVE-2016-1445: Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypass intended ICMP Echo Reply ACLs via vectors related to…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.29%
66.9th percentile
Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypass intended ICMP Echo Reply ACLs via vectors related to subtypes.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | >= 8.2 < 9.4.3.3 | 9.4.3.3 |
| cisco | adaptive_security_appliance_software | >= 9.5.0 < 9.5.2.10 | 9.5.2.10 |
| cisco | adaptive_security_appliance_software | >= 9.6.0 < 9.6.1.5 | 9.6.1.5 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g8vp-hcf8-c48x: Cisco Adaptive Security Appliance (ASA) Software 8
ghsa_unreviewed·2022-05-13
CVE-2016-1445 [MEDIUM] CWE-20 GHSA-g8vp-hcf8-c48x: Cisco Adaptive Security Appliance (ASA) Software 8
Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypass intended ICMP Echo Reply ACLs via vectors related to subtypes.
Cisco
Cisco Adaptive Security Appliance Access Control List ICMP Echo Request Code Filtering Vulnerability
vendor_cisco·2016-07-11·CVSS 4.3
CVE-2016-1445 [MEDIUM] CWE-20 Cisco Adaptive Security Appliance Access Control List ICMP Echo Request Code Filtering Vulnerability
Cisco Adaptive Security Appliance Access Control List ICMP Echo Request Code Filtering Vulnerability
A vulnerability in the Cisco Adaptive Security Appliance (ASA) Software implementation of access control list (ACL) permit and deny filters for ICMP echo reply messages could allow an unauthenticated, remote attacker to bypass ACL configurations for an affected device. ICMP traffic that should be denied may instead be allowed through an affected device.
The vulnerability is due to the implementation of ACL-based filters for ICMP echo requests and the range of ICMP echo request subtypes. An attacker could exploit this vulnerability by sending ICMP echo request traffic to an affected device. A successful exploit could allow the attacker to bypass ACL configurations for the device, which cou
Cisco
Cisco Adaptive Security Appliance Access Control List ICMP Echo Request Code Filtering Vulnerability
vendor_cisco
CVE-2016-1445 Cisco Adaptive Security Appliance Access Control List ICMP Echo Request Code Filtering Vulnerability
CVE-2016-1445: Cisco Adaptive Security Appliance Access Control List ICMP Echo Request Code Filtering Vulnerability
A vulnerability in the Cisco Adaptive Security Appliance (ASA) Software implementation of access control list (ACL) permit and deny filters for ICMP echo reply messages could allow an unauthenticated, remote attacker to bypass ACL configurations for an affected device. ICMP traffic that should be denied may instead be allowed through an affected device. The vulnerability is due to the implementation of ACL-based filters for ICMP echo requests and the range of ICMP echo request subtypes. An attacker could exploit this vulnerability by sending ICMP echo request traffic to an affected device. A successful exploit could allow the attacker to bypass ACL configurations for the devi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160711-asahttp://www.securityfocus.com/bid/91693http://www.securitytracker.com/id/1036271http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160711-asahttp://www.securityfocus.com/bid/91693http://www.securitytracker.com/id/1036271
2016-07-12
Published