ID

VAR-201407-0016


CVE

CVE-2013-5567


TITLE

Cisco Adaptive Security Appliance Service disruption in software (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2013-006613

DESCRIPTION

Cisco Adaptive Security Appliance (ASA) Software 8.4(.6) and earlier, when using an unsupported configuration with overlapping criteria for filtering and inspection, allows remote attackers to cause a denial of service (traffic loop and device crash) via a packet that triggers multiple matches, aka Bug ID CSCui45606. An attacker can exploit this issue to cause the affected device to crash, denying service to legitimate users. This issue is tracked by Cisco Bug ID CSCui45606

Trust: 1.98

sources: NVD: CVE-2013-5567 // JVNDB: JVNDB-2013-006613 // BID: 68504 // VULHUB: VHN-65569

AFFECTED PRODUCTS

vendor:ciscomodel:adaptive security appliance softwarescope:lteversion:8.4\(6\)

Trust: 1.0

vendor:ciscomodel:adaptive security appliancescope: - version: -

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:lteversion:8.4(.6)

Trust: 0.8

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.4\(.4\)

Trust: 0.6

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.4\(.2.8\)

Trust: 0.6

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.4\(.4.3\)

Trust: 0.6

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.4\(.3\)

Trust: 0.6

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.4\(.3.8\)

Trust: 0.6

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.4\(.2.1\)

Trust: 0.6

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.4\(.4.9\)

Trust: 0.6

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.4\(.3.9\)

Trust: 0.6

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.4\(.4.5\)

Trust: 0.6

vendor:ciscomodel:adaptive security appliance softwarescope:eqversion:8.4\(.4.1\)

Trust: 0.6

sources: JVNDB: JVNDB-2013-006613 // CNNVD: CNNVD-201407-306 // NVD: CVE-2013-5567

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-5567
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-5567
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201407-306
value: MEDIUM

Trust: 0.6

VULHUB: VHN-65569
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-5567
severity: MEDIUM
baseScore: 5.4
vectorString: AV:N/AC:H/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-65569
severity: MEDIUM
baseScore: 5.4
vectorString: AV:N/AC:H/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-65569 // JVNDB: JVNDB-2013-006613 // CNNVD: CNNVD-201407-306 // NVD: CVE-2013-5567

PROBLEMTYPE DATA

problemtype:CWE-400

Trust: 1.0

problemtype:CWE-399

Trust: 0.9

sources: VULHUB: VHN-65569 // JVNDB: JVNDB-2013-006613 // NVD: CVE-2013-5567

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201407-306

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201407-306

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-006613

PATCH

title:Cisco ASA Filter and Inspect Overlap Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5567

Trust: 0.8

title:34911url:http://tools.cisco.com/security/center/viewAlert.x?alertId=34911

Trust: 0.8

sources: JVNDB: JVNDB-2013-006613

EXTERNAL IDS

db:NVDid:CVE-2013-5567

Trust: 2.8

db:BIDid:68504

Trust: 2.0

db:SECTRACKid:1030555

Trust: 1.7

db:JVNDBid:JVNDB-2013-006613

Trust: 0.8

db:CNNVDid:CNNVD-201407-306

Trust: 0.7

db:VULHUBid:VHN-65569

Trust: 0.1

sources: VULHUB: VHN-65569 // BID: 68504 // JVNDB: JVNDB-2013-006613 // CNNVD: CNNVD-201407-306 // NVD: CVE-2013-5567

REFERENCES

url:http://www.securityfocus.com/bid/68504

Trust: 1.7

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2013-5567

Trust: 1.7

url:http://tools.cisco.com/security/center/viewalert.x?alertid=34911

Trust: 1.7

url:http://www.securitytracker.com/id/1030555

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/94445

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-5567

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-5567

Trust: 0.8

url:www.cisco.com

Trust: 0.3

sources: VULHUB: VHN-65569 // BID: 68504 // JVNDB: JVNDB-2013-006613 // CNNVD: CNNVD-201407-306 // NVD: CVE-2013-5567

CREDITS

Cisco

Trust: 0.3

sources: BID: 68504

SOURCES

db:VULHUBid:VHN-65569
db:BIDid:68504
db:JVNDBid:JVNDB-2013-006613
db:CNNVDid:CNNVD-201407-306
db:NVDid:CVE-2013-5567

LAST UPDATE DATE

2024-11-23T22:49:30.931000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-65569date:2020-01-21T00:00:00
db:BIDid:68504date:2014-07-10T00:00:00
db:JVNDBid:JVNDB-2013-006613date:2014-07-16T00:00:00
db:CNNVDid:CNNVD-201407-306date:2022-06-06T00:00:00
db:NVDid:CVE-2013-5567date:2024-11-21T01:57:43.117

SOURCES RELEASE DATE

db:VULHUBid:VHN-65569date:2014-07-14T00:00:00
db:BIDid:68504date:2014-07-10T00:00:00
db:JVNDBid:JVNDB-2013-006613date:2014-07-16T00:00:00
db:CNNVDid:CNNVD-201407-306date:2014-07-15T00:00:00
db:NVDid:CVE-2013-5567date:2014-07-14T21:55:05.377