Multiple Cisco Security Notice

Published: 2013-09-02
Last Updated: 2013-09-02 22:19:51 UTC
by Guy Bruneau (Version: 1)
2 comment(s)

"Cisco Adaptive Security Appliance (ASA) Software contains a vulnerability that could allow an unauthenticated, remote attacker to fill the connection table in the ASA preventing new connections to be established through the device."[1]
"A vulnerability in the memory management when executing either the show monitor session all or show monitor session command-line interface (CLI) commands on the Cisco Unified Computing System (UCS) 6100 Series Fabric Interconnects could allow an authenticated, local attacker to trigger a memory leak."[2]
"A vulnerability in the Routing Information Protocol (RIP) process of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the RIP process to crash."[3]
"A vulnerability in Web Administrator Interface of Cisco Wireless LAN Controllers (WLC) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition."[4]

[1] http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3463
[2] http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3467
[3] http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3470
[4] http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3474

-----------

Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu

2 comment(s)

Comments

I am not able to find any more info about #1 other than the link provided.... (which doesn't give any details or software version remedies)...and I am also not seeing it listed here...

http://tools.cisco.com/security/center/publicationListing.x

Did this advisory get pulled after it was first published by any chance?
The other link we have is http://tools.cisco.com/security/center/viewAlert.x?alertId=30607 with:

Version Summary: Cisco Adaptive Security Appliance Software contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service condition. Updates are available.

Diary Archives