SynopsisThe remote device is missing a vendor-supplied security patch.
DescriptionThe remote Cisco ASA device is affected by one or more of the following vulnerabilities :
- A denial of service vulnerability exists due to improper clearing of unused memory blocks after an AnyConnect SSL VPN client disconnects. (CVE-2013-3415)
- A denial of service vulnerability exists resulting from an error in the code that decrypts packets transiting an active VPN tunnel. (CVE-2013-5507)
- A denial of service vulnerability exists due to improper handling of segmented Transparent Network Substrate (TNS) packets. (CVE-2013-5508)
- An authentication bypass vulnerability exists resulting due to an error in handling a client crafted certificate during the authentication phase. (CVE-2013-5509)
- An authentication bypass vulnerability exists due to improper parsing of the LDAP response packet received from a remote AAA LDAP server. (CVE-2013-5510)
- An authentication bypass vulnerability exists due to an error in the implementation of the authentication-certificate option. (CVE-2013-5511)
- A denial of service vulnerability exists due to improper handling of a race condition during inspection of HTTP packets by the HTTP DPI engine. (CVE-2013-5512)
- A denial of service vulnerability exists due to the improper processing of unsupported DNS over TCP packets by the DNS inspection engine. (CVE-2013-5513)
- A denial of service vulnerability exists resulting from the improper handling of crafted HTTPS requests for systems configured for Clientless SSL VPN.
- A denial of service condition can be caused by improper handling of crafted ICMP packets. (CVE-2013-5542)
Note that the verification checks for the presence of CVE-2013-5513 and CVE-2013-5515 are best effort approaches and may result in potential false positives.
SolutionApply the relevant patch referenced in Cisco Security Advisory cisco-sa-20131009-asa.
File Name: cisco-sa-20131009-asa.nasl
CPE: cpe:/a:cisco:adaptive_security_appliance_software, cpe:/h:cisco:asa_5500, cpe:/h:cisco:asa_6500, cpe:/h:cisco:asa_7600, cpe:/h:cisco:asa_1000v
Required KB Items: Host/Cisco/ASA, Host/Cisco/ASA/model
Exploit Ease: No known exploits are available
Patch Publication Date: 10/9/2013
Vulnerability Publication Date: 10/9/2013
CVE: CVE-2013-3415, CVE-2013-5507, CVE-2013-5508, CVE-2013-5509, CVE-2013-5510, CVE-2013-5511, CVE-2013-5512, CVE-2013-5513, CVE-2013-5515, CVE-2013-5542
BID: 62910, 62911, 62912, 62913, 62914, 62915, 62916, 62917, 62919, 63202