MEDIUM · 4.9

CVE-2013-1199

Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive Security Appliances (ASA) devices allows remote authenticated users to cause a de...

Vulnerability Description

Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive Security Appliances (ASA) devices allows remote authenticated users to cause a denial of service (device reload) by accessing resources within multiple sessions, aka Bug ID CSCub58996.

CVSS Score

4.9

MEDIUM

AV:N/AC:H/Au:S/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoAdaptive Security Appliance Clientless Ssl Vpn-
CiscoAdaptive Security Appliance Software-
CiscoAdaptive Security ApplianceAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-1199?

CVE-2013-1199 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive Security Appliances (ASA) devices allows remote authenticated users to cause a de...

How severe is CVE-2013-1199?

CVE-2013-1199 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-1199?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Adaptive Security Appliance Clientless Ssl Vpn, Cisco Adaptive Security Appliance Software, Cisco Adaptive Security Appliance.