CVE-2016-9225

CWE-3994 documents4 sources
Severity
8.6HIGH
EPSS
1.8%
top 17.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1
Latest updateMay 13

Description

A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of IP fragments. An attacker could exploit this vulnerability by sending crafted fragmented IP traffic across the CX module. An exploit could allow the attack

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0

Affected Packages2 packages

CVEListV5all_versions_of_the_asa_cx_context-aware_security_moduleall versions of the ASA CX Context-Aware Security module

🔴Vulnerability Details

2
GHSA
GHSA-847f-22gw-x6h3: A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an u2022-05-13
CVEList
CVE-2016-9225: A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an u2017-02-01

📋Vendor Advisories

1
Cisco
Cisco Adaptive Security Appliance CX Context-Aware Security Denial of Service Vulnerability2017-01-25