Cisco Asa 5580 vulnerabilities
15 known vulnerabilities affecting cisco/asa_5580.
Total CVEs
15
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH8MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2009-4912CRITICALCVSS 10.0≤ 8.1\(1\)2010-06-29
CVE-2009-4912 [CRITICAL] CWE-264 CVE-2009-4912: Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) complete an
Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) complete an SSL handshake with an HTTPS client even if this client is unauthorized, which might allow remote attackers to bypass intended access restrictions via an HTTPS session, aka Bug ID CSCso10876.
nvd
CVE-2009-4919CRITICALCVSS 10.0≤ 8.1\(1\)2010-06-29
CVE-2009-4919 [CRITICAL] CWE-119 CVE-2009-4919: Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before
Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to have an unspecified impact via long IKE attributes, aka Bug ID CSCsu43121.
nvd
CVE-2009-4917HIGHCVSS 7.8≤ 8.1\(1\)2010-06-29
CVE-2009-4917 [HIGH] CVE-2009-4917: Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with softw
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device reload) via a high volume of SIP traffic, aka Bug ID CSCsr65901.
nvd
CVE-2009-4920HIGHCVSS 7.8≤ 8.1\(1\)2010-06-29
CVE-2009-4920 [HIGH] CVE-2009-4920: Unspecified vulnerability in CTM on Cisco Adaptive Security Appliances (ASA) 5580 series devices wit
Unspecified vulnerability in CTM on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software 8.1(2) allows remote attackers to cause a denial of service (watchdog traceback) via a large amount of small-packet data, aka Bug ID CSCsu11412.
nvd
CVE-2009-4914HIGHCVSS 7.8≤ 8.1\(1\)2010-06-29
CVE-2009-4914 [HIGH] CWE-399 CVE-2009-4914: Memory leak on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1
Memory leak on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via Subject Alternative Name fields in an X.509 certificate, aka Bug ID CSCsq17879.
nvd
CVE-2009-4923HIGHCVSS 7.8≤ 8.1\(1\)2010-06-29
CVE-2009-4923 [HIGH] CVE-2009-4923: Unspecified vulnerability in the DTLS implementation on Cisco Adaptive Security Appliances (ASA) 558
Unspecified vulnerability in the DTLS implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (traceback) via TLS fragments, aka Bug ID CSCso53162.
nvd
CVE-2009-4911HIGHCVSS 7.8v8.1\(1\)2010-06-29
CVE-2009-4911 [HIGH] CVE-2009-4911: Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with softw
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device crash) via vectors involving SSL VPN and PPPoE transactions, aka Bug ID CSCsm77958.
nvd
CVE-2009-4921HIGHCVSS 7.8≤ 8.1\(1\)2010-06-29
CVE-2009-4921 [HIGH] CWE-20 CVE-2009-4921: Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remot
Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (traceback) via malformed TCP packets, aka Bug ID CSCsm84110.
nvd
CVE-2009-4915HIGHCVSS 7.8≤ 8.1\(1\)2010-06-29
CVE-2009-4915 [HIGH] CVE-2009-4915: Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with softw
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device reload) via unknown network traffic, as demonstrated by a "connection stress test," aka Bug ID CSCsq68451.
nvd
CVE-2009-4918HIGHCVSS 7.8≤ 8.1\(1\)2010-06-29
CVE-2009-4918 [HIGH] CWE-20 CVE-2009-4918: Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remot
Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (IKE process hang) via malformed NAT-T packets, aka Bug ID CSCsr74439.
nvd
CVE-2009-4910MEDIUMCVSS 4.3≤ 8.1\(1\)2010-06-29
CVE-2009-4910 [MEDIUM] CWE-79 CVE-2009-4910: Cross-site scripting (XSS) vulnerability in the WebVPN portal on Cisco Adaptive Security Appliances
Cross-site scripting (XSS) vulnerability in the WebVPN portal on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCsq78418.
nvd
CVE-2009-4922MEDIUMCVSS 6.8≤ 8.1\(1\)2010-06-29
CVE-2009-4922 [MEDIUM] CVE-2009-4922: Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with softw
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote authenticated users to cause a denial of service (traceback) by establishing many IPsec L2L tunnels from remote peer IP addresses, aka Bug ID CSCso15583.
nvd
CVE-2009-4913MEDIUMCVSS 5.0≤ 8.1\(1\)2010-06-29
CVE-2009-4913 [MEDIUM] CWE-264 CVE-2009-4913: The IPv6 implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with softwar
The IPv6 implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) exposes IP services on the "far side of the box," which might allow remote attackers to bypass intended access restrictions via IPv6 packets, aka Bug ID CSCso58622.
nvd
CVE-2008-7257MEDIUMCVSS 4.3PoCv8.1\(1\)2010-06-29
CVE-2008-7257 [MEDIUM] CWE-20 CVE-2008-7257: CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances
CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary HTTP headers as demonstrated by a redirect attack involving a %0d%0aLocation%3a sequence in a URI, or conduct HTTP response splitting attacks via unspecified
nvd
CVE-2009-4916MEDIUMCVSS 4.0≤ 8.1\(1\)2010-06-29
CVE-2009-4916 [MEDIUM] CVE-2009-4916: Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with softw
Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote authenticated users to cause a denial of service (console hang) via a login action during failover replication, aka Bug ID CSCsq80095.
nvd