PT-2012-4058 · Cisco · Cisco Asa
CVE-2012-2472
·
Publicado
2012-08-06
·
Atualizado
2023-08-15
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Adaptive Security Appliances (ASA) 5500 series devices versions 8.2 through 8.4
Description
The issue allows remote attackers to cause a denial of service via crafted SIP traffic when SIP inspection is enabled. This is due to the creation of many identical pre-allocated secondary pinholes, which can lead to CPU consumption.
Recommendations
For versions 8.2 through 8.4, consider disabling SIP inspection as a temporary workaround until a patch is available. Restrict access to the SIP functionality to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Asa