Vulnerability Name: CVE-2015-0677 (CCN-102088) Assigned: 2015-04-08 Published: 2015-04-08 Updated: 2015-04-23 Summary: The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before 8.6(1.17), 9.0 before 9.0(4.33), 9.1 before 9.1(6), 9.2 before 9.2(3.4), and 9.3 before 9.3(3), when Clientless SSL VPN, AnyConnect SSL VPN, or AnyConnect IKEv2 VPN is used, allows remote attackers to cause a denial of service (VPN outage or device reload) via a crafted XML document, aka Bug ID CSCus95290. CVSS v3 Severity: 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): High
CVSS v2 Severity: 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
Vulnerability Type: CWE-20 Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2015-0677 Source: CCN Type: Cisco Security Advisory ID: cisco-sa-20150408-asaMultiple Vulnerabilities in Cisco ASA Software Source: CISCO Type: Vendor Advisory20150408 Multiple Vulnerabilities in Cisco ASA Software Source: SECTRACK Type: UNKNOWN1032045 Source: XF Type: UNKNOWNcisco-asa-cve20150677-dos(102088) Vulnerable Configuration: Configuration 1 :cpe:/a:cisco:adaptive_security_appliance_software:8.4.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.1.3:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.1.11:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.2:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.2.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.2.8:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.3:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.3.8:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.3.9:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.4:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.4.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.4.3:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.4.5:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.4.9:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.5:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.5.6:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.6:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.7:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.7.3:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.7.15:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.7.22:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.7.23:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.4.7.26:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.6.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.6.1.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.6.1.2:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.6.1.5:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.6.1.10:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.6.1.12:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.6.1.13:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:8.6.1.14:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.2:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.2.10:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.3:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.3.6:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.3.8:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.4:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.4.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.4.5:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.4.7:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.4.17:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.4.20:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.4.24:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.4.26:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.0.4.29:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.1.4:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.2:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.2.8:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.3:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.3.2:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.4:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.4.5:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.5:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.5.10:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.5.12:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.5.15:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.1.5.21:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.2.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.2.2:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.2.2.4:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.2.2.7:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.2.2.8:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.2.3:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.2.3.3:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.3.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.3.1.1:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.3.2:*:*:*:*:*:*:* OR cpe:/a:cisco:adaptive_security_appliance_software:9.3.2.2:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:cisco:adaptive_security_appliance:-:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
cisco adaptive security appliance software 8.4.1
cisco adaptive security appliance software 8.4.1.3
cisco adaptive security appliance software 8.4.1.11
cisco adaptive security appliance software 8.4.2
cisco adaptive security appliance software 8.4.2.1
cisco adaptive security appliance software 8.4.2.8
cisco adaptive security appliance software 8.4.3
cisco adaptive security appliance software 8.4.3.8
cisco adaptive security appliance software 8.4.3.9
cisco adaptive security appliance software 8.4.4
cisco adaptive security appliance software 8.4.4.1
cisco adaptive security appliance software 8.4.4.3
cisco adaptive security appliance software 8.4.4.5
cisco adaptive security appliance software 8.4.4.9
cisco adaptive security appliance software 8.4.5
cisco adaptive security appliance software 8.4.5.6
cisco adaptive security appliance software 8.4.6
cisco adaptive security appliance software 8.4.7
cisco adaptive security appliance software 8.4.7.3
cisco adaptive security appliance software 8.4.7.15
cisco adaptive security appliance software 8.4.7.22
cisco adaptive security appliance software 8.4.7.23
cisco adaptive security appliance software 8.4.7.26
cisco adaptive security appliance software 8.6.1
cisco adaptive security appliance software 8.6.1.1
cisco adaptive security appliance software 8.6.1.2
cisco adaptive security appliance software 8.6.1.5
cisco adaptive security appliance software 8.6.1.10
cisco adaptive security appliance software 8.6.1.12
cisco adaptive security appliance software 8.6.1.13
cisco adaptive security appliance software 8.6.1.14
cisco adaptive security appliance software 9.0.1
cisco adaptive security appliance software 9.0.2
cisco adaptive security appliance software 9.0.2.10
cisco adaptive security appliance software 9.0.3
cisco adaptive security appliance software 9.0.3.6
cisco adaptive security appliance software 9.0.3.8
cisco adaptive security appliance software 9.0.4
cisco adaptive security appliance software 9.0.4.1
cisco adaptive security appliance software 9.0.4.5
cisco adaptive security appliance software 9.0.4.7
cisco adaptive security appliance software 9.0.4.17
cisco adaptive security appliance software 9.0.4.20
cisco adaptive security appliance software 9.0.4.24
cisco adaptive security appliance software 9.0.4.26
cisco adaptive security appliance software 9.0.4.29
cisco adaptive security appliance software 9.1.1
cisco adaptive security appliance software 9.1.1.4
cisco adaptive security appliance software 9.1.2
cisco adaptive security appliance software 9.1.2.8
cisco adaptive security appliance software 9.1.3
cisco adaptive security appliance software 9.1.3.2
cisco adaptive security appliance software 9.1.4
cisco adaptive security appliance software 9.1.4.5
cisco adaptive security appliance software 9.1.5
cisco adaptive security appliance software 9.1.5.10
cisco adaptive security appliance software 9.1.5.12
cisco adaptive security appliance software 9.1.5.15
cisco adaptive security appliance software 9.1.5.21
cisco adaptive security appliance software 9.2.1
cisco adaptive security appliance software 9.2.2
cisco adaptive security appliance software 9.2.2.4
cisco adaptive security appliance software 9.2.2.7
cisco adaptive security appliance software 9.2.2.8
cisco adaptive security appliance software 9.2.3
cisco adaptive security appliance software 9.2.3.3
cisco adaptive security appliance software 9.3.1
cisco adaptive security appliance software 9.3.1.1
cisco adaptive security appliance software 9.3.2
cisco adaptive security appliance software 9.3.2.2
cisco adaptive security appliance -