MEDIUM · 5.4

CVE-2012-5415

Race condition on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (CPU consumption or device reload) by establishing multiple connections, leading...

Vulnerability Description

Race condition on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (CPU consumption or device reload) by establishing multiple connections, leading to improper handling of hash lookups for secondary flows, aka Bug IDs CSCue31622 and CSCuc71272.

CVSS Score

5.4

MEDIUM

AV:N/AC:H/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
Cisco5500 Adaptive Security Appliance7.2
Cisco5500 Series Adaptive Security ApplianceAll versions
CiscoAdaptive Security ApplianceAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-5415?

CVE-2012-5415 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Race condition on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (CPU consumption or device reload) by establishing multiple connections, leading...

How severe is CVE-2012-5415?

CVE-2012-5415 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-5415?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco 5500 Adaptive Security Appliance, Cisco 5500 Series Adaptive Security Appliance, Cisco Adaptive Security Appliance.