Vulnerability Description
Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive Security Appliances (ASA) devices allows remote authenticated users to cause a denial of service (device reload) by accessing resources within multiple sessions, aka Bug ID CSCub58996.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Adaptive Security Appliance Clientless Ssl Vpn | - |
| Cisco | Adaptive Security Appliance Software | - |
| Cisco | Adaptive Security Appliance | All versions |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1199Vendor Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1199Vendor Advisory
FAQ
What is CVE-2013-1199?
CVE-2013-1199 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive Security Appliances (ASA) devices allows remote authenticated users to cause a de...
How severe is CVE-2013-1199?
CVE-2013-1199 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-1199?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Adaptive Security Appliance Clientless Ssl Vpn, Cisco Adaptive Security Appliance Software, Cisco Adaptive Security Appliance.