CVE-2016-9225
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of IP fragments. An attacker could exploit this vulnerability by sending crafted fragmented IP traffic across the CX module. An exploit could allow the attacker to exhaust free packet buffers in shared memory (SHM), causing the CX module to be unable to process further traffic, resulting in a DoS condition. This vulnerability affects all versions of the ASA CX Context-Aware Security module. Cisco has not released and will not release software updates that address this vulnerability. There are no workarounds that address this vulnerability. Cisco Bug IDs: CSCva62946.
Una vulnerabilidad en el manejador de fragmentos de IP de plano de datos del módulo CX Context-Aware Security de Cisco Adaptive Security Appliance (ASA) podrían permitir a un atacante remoto no autenticado provocar que el módulo CX no pudiera procesar más tráfico, resultando en una denegación de servicio (DoS). La vulnerabilidad se debe a un manejo inadecuado de fragmentos IP. Un atacante podría explotar esta vulnerabilidad mediante el envío de tráfico IP fragmentado manipulado a través del módulo CX. Un exploit podría permitir al atacante agotar los búfers de paquetes libres en la SHM, haciendo que el módulo CX no pueda procesar más tráfico, resultando en una condición DoS. Esta vulnerabilidad afecta a todas las versiones del módulo ASA CX Context-Aware Security. Cisco no ha lanzado y no lanzará actualizaciones de software que aborden esta vulnerabilidad. No existen soluciones provisionales que aborden esta vulnerabilidad. ID de errores de Cisco: CSCva62946
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-11-06 CVE Reserved
- 2017-02-01 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/95788 | Third Party Advisory | |
http://www.securitytracker.com/id/1037696 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170125-cas | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.0.1 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.0.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.0.1-40 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.0.1-40" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.0.2 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.0.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.0.2-68 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.0.2-68" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.0_base Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.0_base" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.1.2-29 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.1.2-29" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.1.2-42 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.1.2-42" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.1.3-8 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.1.3-8" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.1.3-10 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.1.3-10" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.1.3-13 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.1.3-13" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.2.1-1 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.2.1-1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.2.2-1 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.2.2-1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.3\(1.1.112\) Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3\(1.1.112\)" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.3.1-1 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.1-1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.3.2-1 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.2-1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.3.3.1-13 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.3.1-13" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.3.4-1 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4-1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.3.4-2 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4-2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.3.4-3 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4-3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.3.4-4 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4-4" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.3.4-5 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4-5" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.3.4-6 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4-6" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.3.4.1.11 Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4.1.11" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Asa Cx Context-aware Security Software Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" | 9.3_base Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3_base" | - |
Affected
|