Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.106037
Category:CISCO
Title:Cisco ASA uRFP Bypass Vulnerability
Summary:Cisco ASA is prone to a Unicast;Reverse Path Forwarding Bypass vulnerability.
Description:Summary:
Cisco ASA is prone to a Unicast
Reverse Path Forwarding Bypass vulnerability.

Vulnerability Insight:
The vulnerability is due to incorrect uRPF
validation where IP packets from an outside interface, whose IP address is both in
the ASA routing table and associated with an internal interface, are not dropped.

Vulnerability Impact:
An unauthenticated, remote attacker could exploit
this vulnerability by sending spoofed IP packets to a targeted ASA in a subnet range
that should be dropped. An exploit could allow the attacker to bypass uRPF validation
on the ASA which would cause packets to be incorrectly forwarded on the internal network.

Affected Software/OS:
Version 9.3 and 9.4

Solution:
Apply the appropriate updates from Cisco.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: BugTraq ID: 76325
Common Vulnerability Exposure (CVE) ID: CVE-2015-4321
Cisco Security Advisory: 20150812 Cisco ASA Unicast Reverse Path Forwarding (uRPF) Bypass Vulnerability
http://tools.cisco.com/security/center/viewAlert.x?alertId=40440
http://www.securitytracker.com/id/1033265
CopyrightThis script is Copyright (C) 2015 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.