Release date:
Updated on:
Affected Systems:
Cisco ASA
Description:
--------------------------------------------------------------------------------
Bugtraq id: 59359
CVE (CAN) ID: CVE-2013-1199
The Cisco ASA 5500 Series Adaptive Security Device is a modular platform for providing security and VPN services. It provides firewall, IPS, anti-X, and VPN services.
In the Clientless ssl vpn component of the Cisco ASA, The rewriter module is subject to competition in the CIFS implementation. authenticated remote attackers access multiple session resources, this vulnerability can cause device overload and denial of service.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1199
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (CVE-2013-1199) and patches for this:
CVE-2013-1199: Cisco ASA Clientless ssl vpn cifs Denial of Service Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1199