Vulnerability Description
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.20), 8.1 before 8.1(2.48), 8.2 before 8.2(3), and 8.3 before 8.3(2.1), when the RIP protocol and the Cisco Phone Proxy functionality are configured, allow remote attackers to cause a denial of service (device reload) via a RIP update, aka Bug ID CSCtg66583.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Adaptive Security Appliance | 8.0\(2\) |
| Cisco | Adaptive Security Appliance Software | 8.0 |
| Cisco | Asa 5500 | All versions |
| Cisco | Asa 5505 | All versions |
| Cisco | Asa 5510 | All versions |
| Cisco | Asa 5520 | All versions |
| Cisco | Asa 5540 | All versions |
| Cisco | Asa 5550 | All versions |
| Cisco | Asa 5580 | All versions |
| Cisco | Pix 500 | All versions |
| Cisco | Pix 501 | All versions |
| Cisco | Pix 506E | All versions |
| Cisco | Pix Firewall 506 | All versions |
| Cisco | Pix Firewall 515 | All versions |
| Cisco | Pix Firewall 520 | All versions |
| Cisco | Pix Firewall 525 | All versions |
| Cisco | Pix Firewall 535 | All versions |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/43488
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14d.sVendor Advisory
- http://www.securitytracker.com/id?1025108
- http://www.vupen.com/english/advisories/2011/0493
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65590
- http://secunia.com/advisories/43488
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14d.sVendor Advisory
- http://www.securitytracker.com/id?1025108
- http://www.vupen.com/english/advisories/2011/0493
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65590
FAQ
What is CVE-2011-0395?
CVE-2011-0395 is a vulnerability with a CVSS score of 7.8 (HIGH). Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.20), 8.1 before 8.1(2.48), 8.2 before 8.2(3), and 8.3 before 8.3(2.1), when the RIP protocol and the Cisco P...
How severe is CVE-2011-0395?
CVE-2011-0395 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-0395?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Adaptive Security Appliance, Cisco Adaptive Security Appliance Software, Cisco Asa 5500, Cisco Asa 5505, Cisco Asa 5510.