ID

VAR-201310-0527


CVE

CVE-2013-5544


TITLE

Cisco Adaptive Security Appliance Software VPN Service operation interruption in authentication function (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2013-004829

DESCRIPTION

The VPN authentication functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to cause a denial of service (device reload) by sending many username-from-cert IKE requests, aka Bug ID CSCua91108. An attacker can exploit this issue to reload the affected device, causing a denial-of-service condition. This issue is being tracked by Cisco Bug ID CSCua91108

Trust: 1.98

sources: NVD: CVE-2013-5544 // JVNDB: JVNDB-2013-004829 // BID: 63262 // VULHUB: VHN-65546

AFFECTED PRODUCTS

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion: -

Trust: 1.6

vendor:ciscomodel:adaptive security appliance softwarescope:lteversion:8.4(4.5)

Trust: 0.8

sources: JVNDB: JVNDB-2013-004829 // CNNVD: CNNVD-201310-508 // NVD: CVE-2013-5544

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-5544
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-5544
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201310-508
value: MEDIUM

Trust: 0.6

VULHUB: VHN-65546
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-5544
severity: MEDIUM
baseScore: 5.4
vectorString: AV:N/AC:H/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-65546
severity: MEDIUM
baseScore: 5.4
vectorString: AV:N/AC:H/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-65546 // JVNDB: JVNDB-2013-004829 // CNNVD: CNNVD-201310-508 // NVD: CVE-2013-5544

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-65546 // JVNDB: JVNDB-2013-004829 // NVD: CVE-2013-5544

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201310-508

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201310-508

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-004829

PATCH

title:Cisco ASA VPN Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5544

Trust: 0.8

title:31397url:http://tools.cisco.com/security/center/viewAlert.x?alertId=31397

Trust: 0.8

sources: JVNDB: JVNDB-2013-004829

EXTERNAL IDS

db:NVDid:CVE-2013-5544

Trust: 2.8

db:JVNDBid:JVNDB-2013-004829

Trust: 0.8

db:CNNVDid:CNNVD-201310-508

Trust: 0.7

db:CISCOid:20131021 CISCO ASA VPN DENIAL OF SERVICE VULNERABILITY

Trust: 0.6

db:BIDid:63262

Trust: 0.4

db:VULHUBid:VHN-65546

Trust: 0.1

sources: VULHUB: VHN-65546 // BID: 63262 // JVNDB: JVNDB-2013-004829 // CNNVD: CNNVD-201310-508 // NVD: CVE-2013-5544

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2013-5544

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-5544

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-5544

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-65546 // BID: 63262 // JVNDB: JVNDB-2013-004829 // CNNVD: CNNVD-201310-508 // NVD: CVE-2013-5544

CREDITS

Cisco

Trust: 0.3

sources: BID: 63262

SOURCES

db:VULHUBid:VHN-65546
db:BIDid:63262
db:JVNDBid:JVNDB-2013-004829
db:CNNVDid:CNNVD-201310-508
db:NVDid:CVE-2013-5544

LAST UPDATE DATE

2024-11-23T22:59:46.370000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-65546date:2013-10-22T00:00:00
db:BIDid:63262date:2013-10-23T00:46:00
db:JVNDBid:JVNDB-2013-004829date:2013-10-23T00:00:00
db:CNNVDid:CNNVD-201310-508date:2013-10-23T00:00:00
db:NVDid:CVE-2013-5544date:2024-11-21T01:57:40.500

SOURCES RELEASE DATE

db:VULHUBid:VHN-65546date:2013-10-22T00:00:00
db:BIDid:63262date:2013-10-21T00:00:00
db:JVNDBid:JVNDB-2013-004829date:2013-10-23T00:00:00
db:CNNVDid:CNNVD-201310-508date:2013-10-23T00:00:00
db:NVDid:CVE-2013-5544date:2013-10-22T11:17:15.500