// For flags

CVE-2016-9225

 

Severity Score

8.6
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of IP fragments. An attacker could exploit this vulnerability by sending crafted fragmented IP traffic across the CX module. An exploit could allow the attacker to exhaust free packet buffers in shared memory (SHM), causing the CX module to be unable to process further traffic, resulting in a DoS condition. This vulnerability affects all versions of the ASA CX Context-Aware Security module. Cisco has not released and will not release software updates that address this vulnerability. There are no workarounds that address this vulnerability. Cisco Bug IDs: CSCva62946.

Una vulnerabilidad en el manejador de fragmentos de IP de plano de datos del módulo CX Context-Aware Security de Cisco Adaptive Security Appliance (ASA) podrían permitir a un atacante remoto no autenticado provocar que el módulo CX no pudiera procesar más tráfico, resultando en una denegación de servicio (DoS). La vulnerabilidad se debe a un manejo inadecuado de fragmentos IP. Un atacante podría explotar esta vulnerabilidad mediante el envío de tráfico IP fragmentado manipulado a través del módulo CX. Un exploit podría permitir al atacante agotar los búfers de paquetes libres en la SHM, haciendo que el módulo CX no pueda procesar más tráfico, resultando en una condición DoS. Esta vulnerabilidad afecta a todas las versiones del módulo ASA CX Context-Aware Security. Cisco no ha lanzado y no lanzará actualizaciones de software que aborden esta vulnerabilidad. No existen soluciones provisionales que aborden esta vulnerabilidad. ID de errores de Cisco: CSCva62946

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-11-06 CVE Reserved
  • 2017-02-01 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.0.1
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.0.1"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.0.1-40
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.0.1-40"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.0.2
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.0.2"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.0.2-68
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.0.2-68"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.0_base
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.0_base"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.1.2-29
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.1.2-29"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.1.2-42
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.1.2-42"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.1.3-8
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.1.3-8"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.1.3-10
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.1.3-10"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.1.3-13
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.1.3-13"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.2.1-1
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.2.1-1"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.2.2-1
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.2.2-1"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.3\(1.1.112\)
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3\(1.1.112\)"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.3.1-1
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.1-1"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.3.2-1
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.2-1"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.3.3.1-13
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.3.1-13"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.3.4-1
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4-1"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.3.4-2
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4-2"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.3.4-3
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4-3"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.3.4-4
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4-4"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.3.4-5
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4-5"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.3.4-6
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4-6"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.3.4.1.11
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3.4.1.11"
-
Affected
Cisco
Search vendor "Cisco"
Asa Cx Context-aware Security Software
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software"
9.3_base
Search vendor "Cisco" for product "Asa Cx Context-aware Security Software" and version "9.3_base"
-
Affected