Denial of service in Cisco Adaptive Security Appliance (ASA) and Cisco ASA 5500-X Series - CVE-2016-6424

 

Denial of service in Cisco Adaptive Security Appliance (ASA) and Cisco ASA 5500-X Series - CVE-2016-6424

Published: October 6, 2016 / Updated: April 5, 2018


Vulnerability identifier: #VU778
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6424
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated user to cause DoS conditions on the target system.

The weakness exists due to improper resource processing. A specially crafted DHCP packets sent by the attackers at specific rates can trigger the target interface to seize up and stop incoming traffic handling.

Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

Affected software

Cisco Adaptive Security Appliance (ASA)
Cisco ASA 5500-X Series

How to mitigate CVE-2016-6424

Install update from vendor's website.


External References

Related Security Bulletins