Description
A vulnerability in the Secure Copy (SCP) feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to the use of an incorrect data type for a length variable. An attacker could exploit this vulnerability by initiating the transfer of a large file to an affected device via SCP. To exploit this vulnerability, the attacker would need to have valid privilege level 15 credentials on the affected device. A successful exploit could allow the attacker to cause the length variable to roll over, which could cause the affected device to crash.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-4284 | A vulnerability in the Secure Copy (SCP) feature of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to the use of an incorrect data type for a length variable. An attacker could exploit this vulnerability by initiating the transfer of a large file to an affected device via SCP. To exploit this vulnerability, the attacker would need to have valid privilege level 15 credentials on the affected device. A successful exploit could allow the attacker to cause the length variable to roll over, which could cause the affected device to crash. |
References
History
Thu, 21 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Cisco
Subscribe
Adaptive Security Appliance
Subscribe
Adaptive Security Appliance Software
Subscribe
Asa 5505
Subscribe
Asa 5510
Subscribe
Asa 5512-x
Subscribe
Asa 5515-x
Subscribe
Asa 5520
Subscribe
Asa 5525-x
Subscribe
Asa 5550
Subscribe
Asa 5555-x
Subscribe
Asa 5580
Subscribe
Asa 5585-x
Subscribe
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-21T19:12:21.527Z
Reserved: 2019-06-04T00:00:00.000Z
Link: CVE-2019-12693
Updated: 2024-08-04T23:24:39.256Z
Status : Modified
Published: 2019-10-02T19:15:13.327
Modified: 2024-11-21T04:23:22.473
Link: CVE-2019-12693
No data.
OpenCVE Enrichment
No data.
EUVD