Description
A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition.
Published: 2019-05-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Administrators can use the vpn-sessiondb logoff all command on the affected device to temporarily clear the condition or reboot the device.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-10262 A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition.
History

Tue, 19 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Adaptive Security Appliance Software Asa 5506-x Asa 5506h-x Asa 5506w-x Asa 5508-x Asa 5516-x Asa 5525-x Asa 5545-x Asa 5555-x
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-19T19:08:38.242Z

Reserved: 2018-12-06T00:00:00.000Z

Link: CVE-2019-1705

cve-icon Vulnrichment

Updated: 2024-08-04T18:28:42.328Z

cve-icon NVD

Status : Modified

Published: 2019-05-03T16:29:00.553

Modified: 2024-11-21T04:37:08.510

Link: CVE-2019-1705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses