Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106770
Category:CISCO
Title:Cisco ASA Software DNS Denial of Service Vulnerability (cisco-sa-20170419-asa-dns)
Summary:A vulnerability in the DNS code of Cisco ASA Software could; allow an unauthenticated, remote attacker to cause an affected device to reload or corrupt the; information present in the device's local DNS cache.
Description:Summary:
A vulnerability in the DNS code of Cisco ASA Software could
allow an unauthenticated, remote attacker to cause an affected device to reload or corrupt the
information present in the device's local DNS cache.

Vulnerability Insight:
The vulnerability is due to a flaw in handling crafted DNS
response messages. An attacker could exploit this vulnerability by triggering a DNS request from
the Cisco ASA Software and replying with a crafted response.

Vulnerability Impact:
A successful exploit could cause the device to reload, resulting
in a denial of service (DoS) condition or corruption of the local DNS cache information.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-6607
BugTraq ID: 97933
http://www.securityfocus.com/bid/97933
http://www.securitytracker.com/id/1038319
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.