ID

VAR-201304-0035


CVE

CVE-2012-5415


TITLE

Cisco Adaptive Security Appliances Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2013-002243

DESCRIPTION

Race condition on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (CPU consumption or device reload) by establishing multiple connections, leading to improper handling of hash lookups for secondary flows, aka Bug IDs CSCue31622 and CSCuc71272. Cisco Adaptive Security Appliance is prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to cause CPU exhaustion and reload an affected device, denying service to legitimate users. This issue is being tracked by Cisco Bug IDs CSCue31622 and CSCuc71272

Trust: 1.98

sources: NVD: CVE-2012-5415 // JVNDB: JVNDB-2013-002243 // BID: 59256 // VULHUB: VHN-58696

AFFECTED PRODUCTS

vendor:ciscomodel:5500 series adaptive security appliancescope:eqversion:7.2

Trust: 1.6

vendor:ciscomodel:5500 adaptive security appliancescope:eqversion:7.2

Trust: 1.6

vendor:ciscomodel:adaptive security appliancescope: - version: -

Trust: 1.4

vendor:ciscomodel:adaptive security appliancescope:eqversion:*

Trust: 1.0

vendor:ciscomodel:5500 series adaptive security appliancescope:eqversion:*

Trust: 1.0

vendor:ciscomodel:adaptive security appliance 5500 seriesscope:eqversion:none

Trust: 0.8

vendor:ciscomodel:adaptive security appliance 5500 seriesscope:eqversion:7.2

Trust: 0.8

vendor:ciscomodel:5500 series adaptive security appliancescope: - version: -

Trust: 0.6

vendor:ciscomodel:asa series adaptive security appliancesscope:eqversion:55000

Trust: 0.3

vendor:ciscomodel:asa series adaptive security appliancescope:eqversion:55007.2.2

Trust: 0.3

vendor:ciscomodel:asa series adaptive security appliancescope:eqversion:55007.2

Trust: 0.3

vendor:ciscomodel:adaptive security appliancescope:eqversion:0

Trust: 0.3

sources: BID: 59256 // JVNDB: JVNDB-2013-002243 // CNNVD: CNNVD-201304-229 // NVD: CVE-2012-5415

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-5415
value: MEDIUM

Trust: 1.0

NVD: CVE-2012-5415
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201304-229
value: MEDIUM

Trust: 0.6

VULHUB: VHN-58696
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2012-5415
severity: MEDIUM
baseScore: 5.4
vectorString: AV:N/AC:H/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-58696
severity: MEDIUM
baseScore: 5.4
vectorString: AV:N/AC:H/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-58696 // JVNDB: JVNDB-2013-002243 // CNNVD: CNNVD-201304-229 // NVD: CVE-2012-5415

PROBLEMTYPE DATA

problemtype:CWE-362

Trust: 1.9

sources: VULHUB: VHN-58696 // JVNDB: JVNDB-2013-002243 // NVD: CVE-2012-5415

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201304-229

TYPE

competitive condition

Trust: 0.6

sources: CNNVD: CNNVD-201304-229

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-002243

PATCH

title:Secondary Flows Lookup Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2012-5415

Trust: 0.8

sources: JVNDB: JVNDB-2013-002243

EXTERNAL IDS

db:NVDid:CVE-2012-5415

Trust: 2.8

db:JVNDBid:JVNDB-2013-002243

Trust: 0.8

db:CNNVDid:CNNVD-201304-229

Trust: 0.7

db:CISCOid:20130411 SECONDARY FLOWS LOOKUP DENIAL OF SERVICE VULNERABILITY

Trust: 0.6

db:BIDid:59256

Trust: 0.4

db:VULHUBid:VHN-58696

Trust: 0.1

sources: VULHUB: VHN-58696 // BID: 59256 // JVNDB: JVNDB-2013-002243 // CNNVD: CNNVD-201304-229 // NVD: CVE-2012-5415

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2012-5415

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-5415

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-5415

Trust: 0.8

url:http://www.cisco.com/en/us/products/ps6120/index.html

Trust: 0.3

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-58696 // BID: 59256 // JVNDB: JVNDB-2013-002243 // CNNVD: CNNVD-201304-229 // NVD: CVE-2012-5415

CREDITS

Cisco

Trust: 0.3

sources: BID: 59256

SOURCES

db:VULHUBid:VHN-58696
db:BIDid:59256
db:JVNDBid:JVNDB-2013-002243
db:CNNVDid:CNNVD-201304-229
db:NVDid:CVE-2012-5415

LAST UPDATE DATE

2024-11-23T22:35:24.472000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-58696date:2013-04-16T00:00:00
db:BIDid:59256date:2013-04-11T00:00:00
db:JVNDBid:JVNDB-2013-002243date:2013-04-17T00:00:00
db:CNNVDid:CNNVD-201304-229date:2013-04-17T00:00:00
db:NVDid:CVE-2012-5415date:2024-11-21T01:44:40.197

SOURCES RELEASE DATE

db:VULHUBid:VHN-58696date:2013-04-16T00:00:00
db:BIDid:59256date:2013-04-11T00:00:00
db:JVNDBid:JVNDB-2013-002243date:2013-04-17T00:00:00
db:CNNVDid:CNNVD-201304-229date:2013-04-17T00:00:00
db:NVDid:CVE-2012-5415date:2013-04-16T14:04:30.890