漏洞标题
思科自适应安全设备软件SSL VPN拒绝服务漏洞
漏洞描述信息
Cisco适应性安全设备(ASA)软件的SSL虚拟私有网络(VPN)功能存在漏洞,该漏洞可能允许经过身份验证的远程攻击者发起拒绝服务(DoS)攻击,阻止受影响设备上创建新的SSL/传输层安全(TLS)连接。该漏洞是由于Base64编码字符串处理不当导致的。攻击者可以通过向受影响设备打开大量SSL VPN会话来利用此漏洞。攻击者需要在受影响的设备上拥有有效的用户凭据才能利用此漏洞。成功的利用可能导致攻击者覆盖特殊的系统内存位置,最终导致设备上新SSL/TLS会话的内存分配错误,从而阻止这些会话成功建立。需要重新加载设备才能从这种情况中恢复。设备上已建立的SSL/TLS连接和通过设备的SSL/TLS连接不受影响。注意:尽管此漏洞位于SSL VPN功能中,但成功利用此漏洞将影响设备上所有新的SSL/TLS会话,包括管理会话。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
漏洞类别
N/A
漏洞标题
Cisco Adaptive Security Appliance Software SSL VPN Denial of Service Vulnerability
漏洞描述信息
A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition that prevents the creation of new SSL/Transport Layer Security (TLS) connections to an affected device. The vulnerability is due to incorrect handling of Base64-encoded strings. An attacker could exploit this vulnerability by opening many SSL VPN sessions to an affected device. The attacker would need to have valid user credentials on the affected device to exploit this vulnerability. A successful exploit could allow the attacker to overwrite a special system memory location, which will eventually result in memory allocation errors for new SSL/TLS sessions to the device, preventing successful establishment of these sessions. A reload of the device is required to recover from this condition. Established SSL/TLS connections to the device and SSL/TLS connections through the device are not affected. Note: Although this vulnerability is in the SSL VPN feature, successful exploitation of this vulnerability would affect all new SSL/TLS sessions to the device, including management sessions.
CVSS信息
N/A
漏洞类别
编码错误
漏洞标题
Cisco Adaptive Security Appliance Software 安全漏洞
漏洞描述信息
Cisco Adaptive Security Appliances Software(ASA Software)是美国思科(Cisco)公司的一套防火墙和网络安全平台。该平台提供了对数据和网络资源的高度安全的访问等功能。 Cisco ASA Software中的Secure Sockets Layer (SSL) VPN功能存在安全漏洞,该漏洞源于程序没有正确处理Base64编码字符串。远程攻击者可通过打开多个SSL VPN会话利用该漏洞造成拒绝服务,进而无法对受影响的设备创建新的SSL/Transpo
CVSS信息
N/A
漏洞类别
其他