MEDIUM
The XML parser in Cisco Adaptive Security Appliance (ASA) Software through 9.5.2 allows remote authenticated users to cause a denial of service (instability, memory consumption, or device reload) by leveraging (1) administrative access or (2) Clientless SSL VPN access to provide a crafted XML document, aka Bug ID CSCut14209
Published May 26, 2016
6.5
MEDIUMCVSS 3.0
EPSS 1.18%
Description
The XML parser in Cisco Adaptive Security Appliance (ASA) Software through 9.5.2 allows remote authenticated users to cause a denial of service (instability, memory consumption, or device reload) by leveraging (1) administrative access or (2) Clientless SSL VPN access to provide a crafted XML document, aka Bug ID CSCut14209.
Affected products
No data.
AND
OR
- 8.4.0
- 8.4.1
- 8.4.1.3
- 8.4.1.11
- 8.4.2
- 8.4.2.1
- 8.4.2.8
- 8.4.3
- 8.4.3.8
- 8.4.3.9
- 8.4.4
- 8.4.4.1
- 8.4.4.3
- 8.4.4.5
- 8.4.4.9
- 8.4.5
- 8.4.5.6
- 8.4.6
- 8.4.7
- 8.4.7.3
- 8.4.7.15
- 8.4.7.22
- 8.4.7.23
- 8.4.7.26
- 8.4.7.28
- 8.4.7.29
- 8.5.1
- 8.5.1.1
- 8.5.1.6
- 8.5.1.7
- 8.5.1.14
- 8.5.1.17
- 8.5.1.18
- 8.5.1.19
- 8.5.1.21
- 8.5.1.24
- 8.6.1
- 8.6.1.1
- 8.6.1.2
- 8.6.1.5
- 8.6.1.10
- 8.6.1.12
- 8.6.1.13
- 8.6.1.14
- 8.6.1.17
- 8.7.1
- 8.7.1.1
- 8.7.1.3
- 8.7.1.4
- 8.7.1.7
- 8.7.1.8
- 8.7.1.11
- 8.7.1.13
- 8.7.1.16
- 8.7.1.17
- 9.0.1
- 9.0.2
- 9.0.2.10
- 9.0.3
- 9.0.3.6
- 9.0.3.8
- 9.0.4
- 9.0.4.1
- 9.0.4.5
- 9.0.4.7
- 9.0.4.17
- 9.0.4.20
- 9.0.4.24
- 9.0.4.26
- 9.0.4.29
- 9.0.4.33
- 9.0.4.35
- 9.0.4.37
- 9.1.1
- 9.1.1.4
- 9.1.2
- 9.1.2.8
- 9.1.3
- 9.1.3.2
- 9.1.4
- 9.1.4.5
- 9.1.5
- 9.1.5.10
- 9.1.5.12
- 9.1.5.15
- 9.1.5.21
- 9.1.6
- 9.1.6.1
- 9.1.6.4
- 9.1.6.6
- 9.1.6.8
- 9.1.6.10
- 9.2\(0.0\)
- 9.2\(0.104\)
- 9.2\(3.1\)
- 9.2.1
- 9.2.2
- 9.2.2.4
- 9.2.2.7
- 9.2.2.8
- 9.2.3
- 9.2.3.3
- 9.2.3.4
- 9.2.4
- 9.2.4.2
- 9.2.4.4
- 9.3\(1.50\)
- 9.3\(1.105\)
- 9.3\(2.100\)
- 9.3\(2.243\)
- 9.3.1
- 9.3.1.1
- 9.3.2
- 9.3.2.2
- 9.3.3
- 9.3.3.1
- 9.3.3.2
- 9.3.3.5
- 9.3.3.6
- 9.3.5
- 9.4.0.115
- 9.4.1
- 9.4.1.1
- 9.4.1.2
- 9.4.1.3
- 9.4.1.5
- 9.4.2
- 9.4.2.3
- 9.5.1
- 9.5.2
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (2)
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160517-asa-xml vendor-advisoryx_refsource_CISCOVendor Advisory
- http://www.securitytracker.com/id/1035976 vdb-entryx_refsource_SECTRACK
| Link | Providers | Tags |
|---|---|---|
| http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160517-asa-xml | vendor-advisoryx_refsource_CISCOVendor Advisory | |
| http://www.securitytracker.com/id/1035976 | vdb-entryx_refsource_SECTRACK |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisco
Published May 26, 2016
Updated Aug 5, 2024
Reserved Jan 4, 2016
Link CVE-2016-1385
CISA Vulnrichment
Updated n/a