Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106341
Category:CISCO
Title:Cisco ASA Software DHCP Relay Denial of Service Vulnerability (cisco-sa-20161005-asa-dhcp)
Summary:A vulnerability in the DHCP Relay feature of Cisco ASA Software; could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition by; causing an interface wedge.
Description:Summary:
A vulnerability in the DHCP Relay feature of Cisco ASA Software
could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition by
causing an interface wedge.

Vulnerability Insight:
The vulnerability is due to improper handling of resources
linked with the DHCP Relay feature. An attacker could exploit this vulnerability by sending DHCP
packets at specific rates.

Vulnerability Impact:
An exploit could allow an attacker to cause an interface to
become wedged, and stop processing incoming traffic. Once this state is reached, restoration of
service can only be achieved by reloading the device.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
6.1

CVSS Vector:
AV:A/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-6424
BugTraq ID: 93408
http://www.securityfocus.com/bid/93408
Cisco Security Advisory: 20161005 Cisco ASA Software DHCP Relay Denial of Service Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-asa-dhcp
http://www.securitytracker.com/id/1036961
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.