The Unicast Reverse Path Forwarding (uRPF) implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(1.50), 9.3(2.100), 9.3(3), and 9.4(1) mishandles cases where an IP address belongs to an internal interface but is also in the ASA routing table, which allows remote attackers to bypass uRPF validation via spoofed packets, aka Bug ID CSCuv60724.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2015-08-20T10:00:00

Updated: 2024-08-06T06:11:12.892Z

Reserved: 2015-06-04T00:00:00

Link: CVE-2015-4321

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2015-08-20T10:59:09.950

Modified: 2023-08-11T18:54:47.730

Link: CVE-2015-4321

cve-icon Redhat

No data.