Vulnerability Name: | CVE-2010-0149 (CCN-56336) | ||||||||
Assigned: | 2010-02-17 | ||||||||
Published: | 2010-02-17 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.2 before 7.2(4.46), 8.0 before 8.0(4.38), 8.1 before 8.1(2.29), and 8.2 before 8.2(1.5); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (prevention of new connections) via crafted TCP segments during termination of the TCP connection that cause the connection to remain in CLOSEWAIT status, aka "TCP Connection Exhaustion Denial of Service Vulnerability." | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 6.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C)
5.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-0149 Source: OSVDB Type: UNKNOWN 62433 Source: CCN Type: SA38618 Cisco ASA 5500 Series Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 38618 Source: CCN Type: SA38636 Cisco PIX 500 Series Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 38636 Source: CCN Type: SECTRACK ID: 1023612 Cisco ASA TCP, SIP, SCCP, DTLS, and IKE Processing Flaws Let Remote Users Deny Service Source: CCN Type: cisco-sa-20100217-asa Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances Source: CISCO Type: Vendor Advisory 20100217 Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances Source: CCN Type: OSVDB ID: 62433 Cisco Multiple Products Series TCP Connection Exhaustion Remote DoS Source: BID Type: UNKNOWN 38275 Source: CCN Type: BID-38275 Cisco ASA Appliance TCP Connection Exhaustion Denial of Service Vulnerability Source: SECTRACK Type: UNKNOWN 1023612 Source: VUPEN Type: Vendor Advisory ADV-2010-0415 Source: XF Type: UNKNOWN cisco-asa-tcp-dos(56336) Source: XF Type: UNKNOWN cisco-asa-tcp-dos(56336) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |