he DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2 before 8.2(5.57), 8.3 before 8.3(2.44), 8.4 before 8.4(7.28), 8.5 before 8.5(1.24), 8.6 before 8.6(1.17), 8.7 before 8.7(1.16), 9.0 before 9.0(4.33), 9.1 before 9.1(6.1), 9.2 before 9.2(3.4), and 9.3 before 9.3(3) allows man-in-the-middle attackers to cause a denial of service (memory consumption or device outage) by triggering outbound DNS queries and then sending crafted responses to these queries, aka Bug ID CSCuq77655.
Configuration 1 (hide)
|
21 Nov 2024, 02:23
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150408-asa - Vendor Advisory | |
| References | () http://www.securitytracker.com/id/1032045 - |
Published : 2015-04-13 01:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-0676
Mitre link : CVE-2015-0676
CVE.ORG link : CVE-2015-0676
JSON object : View
Improper Input Validation