The IKEv2 implementation in Cisco ASA Software 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device reload) via a crafted packet that is sent during tunnel creation, aka Bug ID CSCum96401.
2014-10-10T10:55:06.243
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.8 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | asa | 8.4 | Yes |
Application | cisco | asa | 8.4.1 | Yes |
Application | cisco | asa | 8.4.2 | Yes |
Application | cisco | asa | 8.4.3 | Yes |
Application | cisco | asa | 8.4.4 | Yes |
Application | cisco | asa | 8.6 | Yes |
Application | cisco | asa | 8.6.1 | Yes |
Application | cisco | asa | 9.0 | Yes |
Application | cisco | asa | 9.1 | Yes |
Application | cisco | asa | 9.1.5 | Yes |