Denial of service in Cisco ASA 5500-X Series - CVE-2016-6439

 

Denial of service in Cisco ASA 5500-X Series - CVE-2016-6439

Published: October 19, 2016 / Updated: April 5, 2018


Vulnerability identifier: #VU1047
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-6439
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Cisco ASA 5500-X Series

Detailed vulnerability description

The vulnerability allows a remote anauthenticated user to cause DoS conditions on the target system.
The weakness is due to resource management error. By sending a specially crafted data, attackers can trigger the Snort process restart and bypass Snort detection.
Successful exploitation results in denial of service that may lead to further attacks on the vulnerable system.

How to mitigate CVE-2016-6439

Install update from vendor's website.

Sources