Release date: 2013-09-06
Updated on:
Affected Systems:
Cisco ASA
Description:
--------------------------------------------------------------------------------
Bugtraq id: 62251
CVE (CAN) ID: CVE-2013-3458
The Cisco ASA 5500 Series Adaptive Security Device is a modular platform for providing security and VPN services. It provides firewall, IPS, anti-X, and VPN services.
The Cisco Adaptive Security Appliance (ASA) software does not properly process X.509 certificates when using SMP. A denial of service vulnerability exists, allowing remote attackers to pass a large amount of SSL or TLS traffic, this vulnerability can cause DoS (device crash ).
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3458
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (CVE-2013-3458) and patches for this:
CVE-2013-3458: Cisco ASA Certificate Processing Denial of Service Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3458