CVE-2016-6424
published 2016-10-06CVE-2016-6424: The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4.7.29 and 9.1.7.4 allows remote attackers to cause a denial of service…
PriorityP425medium6.5CVSS 3.0
AVAACLPRNUINSUCNINAH
EPSS
0.88%
55.1th percentile
The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4.7.29 and 9.1.7.4 allows remote attackers to cause a denial of service (interface wedge) via a crafted rate of DHCP packet transmission, aka Bug ID CSCuy66942.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance_software | — | — |
| cisco | adaptive_security_appliance_software | — | — |
| cisco | asa | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ASA Software DHCP Relay Denial of Service Vulnerability
vendor_cisco·2016-10-05·CVSS 6.1
CVE-2016-6424 [MEDIUM] CWE-399 Cisco ASA Software DHCP Relay Denial of Service Vulnerability
Cisco ASA Software DHCP Relay Denial of Service Vulnerability
A vulnerability in the DHCP Relay feature of Cisco ASA Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition by causing an interface wedge.
The vulnerability is due to improper handling of resources linked with the DHCP Relay feature. An attacker could exploit this vulnerability by sending DHCP packets at specific rates. An exploit could allow an attacker to cause an interface to become wedged, and stop processing incoming traffic. Once this state is reached, restoration of service can only be achieved by reloading the device.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is a
Cisco
Cisco ASA Software DHCP Relay Denial of Service Vulnerability
vendor_cisco
CVE-2016-6424 Cisco ASA Software DHCP Relay Denial of Service Vulnerability
CVE-2016-6424: Cisco ASA Software DHCP Relay Denial of Service Vulnerability
A vulnerability in the DHCP Relay feature of Cisco ASA Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition by causing an interface wedge. The vulnerability is due to improper handling of resources linked with the DHCP Relay feature. An attacker could exploit this vulnerability by sending DHCP packets at specific rates. An exploit could allow an attacker to cause an interface to become wedged, and stop processing incoming traffic. Once this state is reached, restoration of service can only be achieved by reloading the device. Cisco has released software updates that address this vulnerability.
CWE: CWE-399, CWE-399
Bug IDs: CSCuy66942
GHSA
GHSA-mrrg-x8wc-mhcg: The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8
ghsa_unreviewed·2022-05-14
CVE-2016-6424 [MEDIUM] GHSA-mrrg-x8wc-mhcg: The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8
The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4.7.29 and 9.1.7.4 allows remote attackers to cause a denial of service (interface wedge) via a crafted rate of DHCP packet transmission, aka Bug ID CSCuy66942.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-asa-dhcphttp://www.securityfocus.com/bid/93408http://www.securitytracker.com/id/1036961http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-asa-dhcphttp://www.securityfocus.com/bid/93408http://www.securitytracker.com/id/1036961
2016-10-06
Published