Lucene search

K
cveCiscoCVE-2008-2735
HistorySep 04, 2008 - 4:41 p.m.

CVE-2008-2735

2008-09-0416:41:00
CWE-20
cisco
web.nvd.nist.gov
24
cisco
asa
5500
http server
denial of service
vulnerability
ssl
vpn
bug id
cscsq19369

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

6.6

Confidence

Low

EPSS

0.021

Percentile

89.5%

The HTTP server in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0 before 8.0(3)15 and 8.1 before 8.1(1)5, when configured as a clientless SSL VPN endpoint, does not properly process URIs, which allows remote attackers to cause a denial of service (device reload) via a URI in a crafted SSL or HTTP packet, aka Bug ID CSCsq19369.

Affected configurations

Nvd
Node
ciscoadaptive_security_appliance_5500Match8.0
OR
ciscoadaptive_security_appliance_5500Match8.1
VendorProductVersionCPE
ciscoadaptive_security_appliance_55008.0cpe:2.3:h:cisco:adaptive_security_appliance_5500:8.0:*:*:*:*:*:*:*
ciscoadaptive_security_appliance_55008.1cpe:2.3:h:cisco:adaptive_security_appliance_5500:8.1:*:*:*:*:*:*:*

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

6.6

Confidence

Low

EPSS

0.021

Percentile

89.5%