A vulnerability in the Secure Copy (SCP) feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to the use of an incorrect data type for a length variable. An attacker could exploit this vulnerability by initiating the transfer of a large file to an affected device via SCP. To exploit this vulnerability, the attacker would need to have valid privilege level 15 credentials on the affected device. A successful exploit could allow the attacker to cause the length variable to roll over, which could cause the affected device to crash.
2019-10-02T19:15:13.327
2024-11-21T04:23:22.473
Modified
CVSSv3.1: 4.9 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | adaptive_security_appliance | < 9.6.4.30 | Yes |
Operating System | cisco | adaptive_security_appliance_software | < 9.8.4 | Yes |
Operating System | cisco | adaptive_security_appliance_software | < 9.9.2.50 | Yes |
Operating System | cisco | adaptive_security_appliance_software | < 9.10.1.22 | Yes |
Operating System | cisco | adaptive_security_appliance_software | < 9.12.2.1 | Yes |
Hardware | cisco | asa_5505 | - | No |
Hardware | cisco | asa_5510 | - | No |
Hardware | cisco | asa_5512-x | - | No |
Hardware | cisco | asa_5515-x | - | No |
Hardware | cisco | asa_5520 | - | No |
Hardware | cisco | asa_5525-x | - | No |
Hardware | cisco | asa_5550 | - | No |
Hardware | cisco | asa_5555-x | - | No |
Hardware | cisco | asa_5580 | - | No |
Hardware | cisco | asa_5585-x | - | No |