Race condition in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)19, when using "clientless SSL VPNs," allows remote attackers to cause a denial of service (device reload) via "non-standard SSL sessions."
2007-05-02T22:19:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.1 (HIGH)
AV:N/AC:M/Au:N/C:N/I:N/A:C
8.6
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Hardware | cisco | pix | ≤ 7.2 | Yes |
Hardware | cisco | pix | 7.1 | Yes |
Operating System | cisco | adaptive_security_appliance_software | ≤ 7.2.2 | Yes |
Operating System | cisco | adaptive_security_appliance_software | 7.1 | Yes |